CVE-2026-82485: itsourcecode Sales and Inventory System pro_edit.php sql injection
Published Aug 30, 2026
·Updated
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/proedit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
itsourcecode Sales and Inventory System=1.0
Event History
Aug 30, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker must have low-level privileges. No user interaction is required.
2
What component should be prioritized for remediation?
The affected functionality is in /pages/pro_edit.php, where manipulation of the ID argument can lead to SQL injection in Sales and Inventory System 1.0.
3
Is public exploitation information available?
Yes. The exploit has been publicly disclosed and may be used.