Executive brief
itsourcecode Sales and Inventory System is a free PHP-based inventory management application used for tracking and managing product sales and stock. A SQL injection vulnerability in the inventory edit function allows authenticated attackers to inject malicious database commands through the ID parameter, potentially exposing sensitive business data, corrupting inventory records, or gaining unauthorized system access.
Technical details
The vulnerability is a SQL injection flaw in /pages/inv_edit1.php where the 'id' parameter is not properly sanitized before being used in SQL queries. The attack requires valid authentication credentials and is remotely exploitable via POST requests. An attacker can inject arbitrary SQL code (e.g., SLEEP() for time-based detection or UNION SELECT for data exfiltration) to manipulate database operations, extract sensitive data, or modify database records. The vendor recommends using prepared statements with parameter binding, implementing strict input validation, restricting database user permissions, and conducting regular security audits. No official patch has been announced at time of public disclosure.
Affected products
- itsourcecode Sales and Inventory System 1.0
Timeline
- 2026-08-03: disclosed: Vulnerability disclosed on GitHub
- 2026-09-13: advisory: CVE-2026-90600 published to NVD