Executive brief
itsourcecode Sales and Inventory System is a PHP-based web application used for managing sales and inventory operations. A SQL injection vulnerability in the user edit page allows authenticated attackers to inject malicious SQL commands through the ID parameter, potentially leading to unauthorized database access, data theft, data modification, or complete system compromise.
Technical details
A SQL injection vulnerability exists in the /pages/us_edit.php file of itsourcecode Sales and Inventory System version 1.0, where the 'id' parameter is not properly sanitized before being used in SQL queries. The vulnerability is accessible to authenticated users and can be exploited via GET requests with specially crafted SQL payloads (e.g., using GTID_SUBSET functions to detect blind SQL injection conditions). An attacker with valid login credentials can manipulate the 'id' parameter to extract sensitive data from the database, modify data, or potentially execute arbitrary database commands. The recommended fix involves implementing prepared statements with parameter binding, strict input validation to ensure numeric format, and applying the principle of least privilege to database accounts. No patch has been announced at this time.
Affected products
- itsourcecode Sales and Inventory System 1.0
Timeline
- 2026-07-30: disclosed: Vulnerability disclosed on GitHub
- 2026-09-08: advisory: CVE-2026-86675 published on NVD