CVE-2026-90700: itsourcecode Sales and Inventory System pro_edit1.php sql injection
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/proedit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the CVSS vector indicates that the attacker needs low-level privileges. No user interaction is required.
What is the impact of successful exploitation?
Successful SQL injection can affect confidentiality, integrity, and availability at a low impact level according to the CVSS metrics. The vulnerable input is the prodcode argument handled by /pages/pro_edit1.php.
How urgent is remediation?
The issue is rated medium severity with a CVSS score of 6.3. Public exploit disclosure is noted, which may increase the likelihood of exploitation.