CVE-2026-86234: itsourcecode Sales and Inventory System cust_transac.php add sql injection
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/custtransac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the CVSS vector indicates that low privileges are required. No user interaction is required.
Which request parameter and endpoint should defenders prioritize for detection?
Focus on requests to /pages/cust_transac.php?action=add, particularly values supplied in the firstname argument. Unexpected SQL syntax or database error responses associated with this request may indicate attempted exploitation.
How urgent is mitigation?
A public exploit is available, so systems running the affected Sales and Inventory System 1.0 should be treated as exposed where low-privileged remote access is possible. The reported impact includes limited confidentiality, integrity, and availability effects.