CVE-2026-86310: itsourcecode Sales and Inventory System cust_edit1.php sql injection
Published Sep 7, 2026
·Updated
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/custedit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
itsourcecode Sales and Inventory System=1.0
Event History
Sep 7, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need before attempting exploitation?
The CVSS vector indicates low privileges are required. No user interaction is required after the attacker has the necessary access.
2
What impact should be expected if exploitation succeeds?
The reported CVSS metrics indicate low impact to confidentiality, integrity, and availability. The vulnerability is classified as SQL injection.
3
How urgent is triage for exposed deployments?
A public exploit has been disclosed and may be used. The documented affected release is itsourcecode Sales and Inventory System 1.0.