Junglewise Threat Intelligence

CVE-2026-82484: itsourcecode Sales and Inventory System SQL injection in emp_searchfrm.php

CVE-2026-82484 · Severity: medium · CVSS 6.3 · Published 2026-08-30

Vendors: Itsourcecode.

Executive brief

itsourcecode Sales and Inventory System is a free PHP/MySQL application used to manage sales and inventory operations. A SQL injection vulnerability in the employee search page allows authenticated attackers to manipulate database queries, potentially leading to unauthorized data access, data theft, modification of business records, or complete system compromise.

Technical details

A SQL injection vulnerability exists in the /pages/emp_searchfrm.php file where the 'id' parameter is not properly sanitized before being used in SQL queries. The vulnerability requires valid authentication (the attack is conducted after login with credentials), but is remotely accessible over the network. An attacker can inject malicious SQL code through the 'id' parameter to extract sensitive data, modify database records, or escalate their privileges. Remediation involves implementing prepared statements, input validation, and applying least-privilege database permissions.

Affected products

  • itsourcecode Sales and Inventory System 1.0

Timeline

  • 2026-07-14: disclosed
  • 2026-08-30: advisory

References