Executive brief
itsourcecode Sales and Inventory System is a free PHP/MySQL application for managing sales and inventory operations. A SQL injection vulnerability in the product search function allows authenticated attackers to manipulate database queries through unsanitized input, potentially leading to unauthorized data access, theft of sensitive information, data corruption, or complete system compromise.
Technical details
The vulnerability is a SQL injection flaw in the /pages/pro_searchfrm.php file where the 'id' parameter is not properly sanitized before use in SQL queries. Although the vulnerability requires valid authentication (attacker must be logged in), it can be exploited via network access by injecting malicious SQL code into the id parameter. A proof-of-concept demonstrates time-based blind SQL injection using MySQL functions. Successful exploitation allows attackers to extract sensitive data, modify records, or gain comprehensive database control. Remediation requires implementing prepared statements with parameter binding, strict input validation, principle of least privilege for database credentials, and regular security audits.
Affected products
- itsourcecode Sales and Inventory System 1.0
Timeline
- 2026-07-18: disclosed
- 2026-09-07: advisory