Executive brief
Sales and Inventory System is a free PHP/MySQL application used to manage employee and inventory data for small to medium businesses. A SQL injection vulnerability in the employee edit form allows authenticated attackers to manipulate database queries by injecting malicious code through the ID parameter, potentially exposing sensitive employee and business data or modifying system information.
Technical details
This is a SQL injection vulnerability in the /pages/emp_edit1.php file affecting the 'id' parameter. The vulnerability exists because user input is not properly sanitized or validated before being used in SQL queries. The attack requires authentication (valid user session cookie required, as shown in the POC), but once authenticated, an attacker can inject arbitrary SQL through the 'id' parameter to extract sensitive data, modify records, or potentially achieve broader database compromise. The proof-of-concept demonstrates boolean-based blind SQL injection using the GTID_SUBSET function. Remediation involves implementing prepared statements with parameterized queries, input validation to ensure the ID matches expected numeric patterns, and restricting database user permissions to the minimum necessary.
Affected products
- itsourcecode Sales and Inventory System 1.0
Timeline
- 2026-07-24: disclosed
- 2026-09-07: published