CVE-2026-82609: itsourcecode Sales and Inventory System inv_edit.php sql injection
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/invedit.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Deployments of itsourcecode Sales and Inventory System 1.0 are affected where the /pages/inv_edit.php endpoint is reachable by an attacker. The attack can be initiated remotely.
What access does an attacker need to exploit it?
The CVSS vector indicates low privileges are required and no user interaction is needed. Exploitation involves manipulating the ID argument handled by /pages/inv_edit.php.
Is public exploit code available?
Yes. The available data states that a public exploit exists and may be used.
What is the potential impact of successful exploitation?
Successful SQL injection may affect the confidentiality, integrity, and availability of the affected system, each with a low CVSS impact rating.