Executive brief
itsourcecode Sales and Inventory System is a free PHP/MySQL-based application used for managing sales and inventory operations. A SQL injection vulnerability in the login processing file allows attackers to inject malicious SQL code through the user parameter, potentially leading to unauthorized database access, data theft, modification of records, and complete system compromise.
Technical details
A SQL injection vulnerability exists in the /pages/processlogin.php file of itsourcecode Sales and Inventory System version 1.0, where the 'user' parameter is not properly sanitized before being used in SQL queries. The vulnerability can be exploited remotely by an attacker crafting a malicious POST request with SQL injection payloads in the user field. Attackers can manipulate SQL queries to extract sensitive data, modify database records, bypass authentication, or potentially achieve full system control. The application should implement prepared statements and parameter binding to prevent this vulnerability. As of the advisory date (August 24, 2026), it is unclear whether a patch has been released.
Affected products
- itsourcecode Sales and Inventory System 1.0
Timeline
- 2026-07-09: disclosed: Vulnerability disclosed on GitHub issue
- 2026-08-24: advisory: CVE-2026-78171 published