CVE-2026-82545: itsourcecode Sales and Inventory System sup_searchfrm.php sql injection
Published Aug 30, 2026
·Updated
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/supsearchfrm.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
itsourcecode Sales and Inventory System=1.0
Event History
Aug 30, 2026
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack vector is network-based and requires low privileges. No user interaction is required.
2
Is exploit code or public exploitation information available?
The exploit has been publicly disclosed and may be used by attackers.
3
What is the expected security impact if exploitation succeeds?
The assigned CVSS vector indicates low impact to confidentiality, integrity, and availability.