CVE-2026-90600: itsourcecode Sales and Inventory System inv_edit1.php sql injection
Published Sep 13, 2026
·Updated
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/invedit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
itsourcecode Sales and Inventory System=1.0
Event History
Sep 13, 2026
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be prioritized for remediation?
Instances of itsourcecode Sales and Inventory System 1.0 should be prioritized, particularly where the application is remotely reachable and exposes the affected inv_edit1.php functionality.
2
What does an attacker need to exploit this issue?
The vector indicates remote network access, low privileges, and no user interaction. Exploitation involves controlling the ID argument.
3
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.