CVE-2026-86233: itsourcecode Sales and Inventory System us_del.php sql injection
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/usdel.php?type=user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access to the application and low-privileged access, as reflected by the PR:L vector. No user interaction is required.
Which endpoint and parameter should be prioritized for review?
Review requests to /pages/us_del.php?type=user, specifically the ID argument. The reported issue is SQL injection caused by manipulation of that argument.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used, increasing the likelihood of attempted exploitation.
What impact is reported if exploitation succeeds?
The vulnerability is rated medium with a 6.3 CVSS score and has low reported impact on confidentiality, integrity, and availability.