CVE-2026-86291: itsourcecode Sales and Inventory System us_edit1.php sql injection
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/usedit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the CVSS vector indicates that the attacker needs low-level privileges. No user interaction is required.
Which deployments are affected?
The affected product is itsourcecode Sales and Inventory System version 1.0. The vulnerable endpoint is /pages/us_edit1.php, where manipulation of the ID argument can lead to SQL injection.
Is exploitation likely to be practical?
The vulnerability has low attack complexity, and a public exploit has been disclosed. This increases the likelihood that attackers with the required privileges may attempt exploitation.