Executive brief
itsourcecode Sales and Inventory System is a free PHP/MySQL application used for managing inventory and customer data. A SQL injection vulnerability in the customer edit page allows authenticated attackers to manipulate database queries through the 'id' parameter, potentially leading to unauthorized data access, modification, or deletion.
Technical details
A SQL injection vulnerability exists in /pages/cust_edit.php where user-supplied input in the 'id' parameter is not properly sanitized before being used in SQL queries. The vulnerability is exploitable remotely by authenticated users who can craft malicious SQL payloads in the query string (e.g., via UNION-based or time-based blind injection). An attacker with valid login credentials can extract sensitive database information, modify or delete records, or potentially achieve broader system compromise depending on database user permissions. The fix requires implementing prepared statements with parameterized queries and strict input validation on the 'id' parameter to ensure it matches expected numeric patterns.
Affected products
- itsourcecode Sales and Inventory System 1.0
Timeline
- 2026-07-10: disclosed
- 2026-08-24: advisory
- other: Exploit public and may be in use