Junglewise Threat Intelligence

CVE-2026-82541: itsourcecode Sales and Inventory System SQL injection in sup_edit.php

CVE-2026-82541 · Severity: medium · CVSS 6.3 · Published 2026-08-30

Vendors: Itsourcecode.

Executive brief

itsourcecode Sales and Inventory System is a free PHP-based application used to manage sales and inventory operations. A SQL injection vulnerability in the supplier edit page allows authenticated attackers to manipulate database queries through unsanitized input, potentially leading to unauthorized data access, modification, or system compromise.

Technical details

A SQL injection vulnerability exists in the /pages/sup_edit.php file of Sales and Inventory System version 1.0, where the 'id' parameter fails to properly sanitize or validate user input before use in SQL queries. The vulnerability requires authentication (valid PHPSESSID cookie) and network access to the application. Attackers can inject malicious SQL through the id parameter to extract sensitive data, modify database records, or potentially execute administrative operations. The root cause is improper input validation and lack of prepared statements or parameterized queries. Fix: implement prepared statements with parameter binding, strict input validation for numeric IDs, and principle of least privilege for database credentials.

Affected products

  • itsourcecode Sales and Inventory System 1.0

Timeline

  • 2026-07-14: disclosed
  • 2026-08-30: advisory

References