CVE-2026-85383: itsourcecode Sales and Inventory System inv_del.php sql injection
Published Sep 4, 2026
·Updated
A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/invdel.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
1 affected component
itsourcecode Sales and Inventory System=1.0
Event History
Sep 4, 2026
CVE Published
via MITRE·01:45 AM
Data Sourced
via MITRE·01:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack can be executed remotely, but the CVSS vector indicates that low-level privileges are required. No user interaction is required.
2
Which input should be investigated for signs of exploitation?
Investigate requests to /pages/inv_del.php that manipulate the ID argument. The vulnerable behavior is SQL injection through that argument.
3
How likely is active exploitation?
An exploit has been published and may be used. The CVSS temporal metrics also identify exploit code maturity as proof-of-concept.