CVE-2026-86517: itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection
Published Sep 8, 2026
·Updated
A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqliquery of the file /pages/ussearchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
2 affected components
itsourcecode Sales and Inventory System=1.0
mysqli_query
Event History
Sep 8, 2026
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack can be launched remotely and requires low privileges. No user interaction is required.
2
Which deployment should be prioritized for remediation?
Prioritize instances of itsourcecode Sales and Inventory System 1.0 that expose or use /pages/us_searchfrm.php. The vulnerable input is the ID argument passed to mysqli_query.
3
Is public exploit information available?
Yes. An exploit has been published and may be used, increasing the likelihood of attempted exploitation.