CVE-2026-86163: itsourcecode Sales and Inventory System pro_del.php sql injection
Published Sep 6, 2026
·Updated
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/prodel.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Affected Software
1 affected component
itsourcecode Sales and Inventory System=1.0
Event History
Sep 6, 2026
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The CVSS vector indicates that an attacker needs low-level privileges. No user interaction is required.
2
Can this be exploited from outside the local network?
Yes. The vulnerability is rated with network attack vector and is described as remotely exploitable.
3
How likely is exploitation in practice?
A public exploit is available, and the exploit maturity is rated as proof-of-concept. This can lower the effort needed for an attacker who already has the required low-level access.