CVE-2026-86265: itsourcecode Sales and Inventory System us_transac.php sql injection
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/ustransac.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the CVSS vector indicates that low privileges are required. No user interaction is required.
Which deployments should be considered exposed?
Sales and Inventory System 1.0 deployments with the /pages/us_transac.php endpoint should be considered potentially affected, specifically where the Username argument is reachable by a low-privileged user.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.
How can I check for attempted exploitation?
Review web and application logs for requests to /pages/us_transac.php containing unusual or SQL-like values in the Username parameter. The provided information does not identify specific payloads or indicators of compromise.