Executive brief
itsourcecode Sales and Inventory System is a free PHP/MySQL application used to manage sales and inventory operations. A SQL injection vulnerability in the employee search page allows authenticated attackers to manipulate database queries, potentially leading to unauthorized data access, data theft, modification of business records, or complete system compromise.
Technical details
A SQL injection vulnerability exists in the /pages/emp_searchfrm.php file where the 'id' parameter is not properly sanitized before being used in SQL queries. The vulnerability requires valid authentication (the attack is conducted after login with credentials), but is remotely accessible over the network. An attacker can inject malicious SQL code through the 'id' parameter to extract sensitive data, modify database records, or escalate their privileges. Remediation involves implementing prepared statements, input validation, and applying least-privilege database permissions.
Affected products
- itsourcecode Sales and Inventory System 1.0
Timeline
- 2026-07-14: disclosed
- 2026-08-30: advisory