CVE-2026-82541: itsourcecode Sales and Inventory System sup_edit.php sql injection
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/supedit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack is remotely executable, but the CVSS vector indicates low-level privileges are required. No user interaction is required.
Is exploit code available?
Yes. A public exploit has been released, which increases the likelihood of attempted exploitation.
Which deployments should be considered exposed?
Deployments of itsourcecode Sales and Inventory System 1.0 should be assessed, particularly where the /pages/sup_edit.php endpoint is reachable by low-privileged authenticated users.