Junglewise Threat Intelligence

CVE-2026-90700: itsourcecode Sales and Inventory System SQL injection in product edit

CVE-2026-90700 · Severity: medium · CVSS 6.3 · Published 2026-09-14

Vendors: Itsourcecode.

Executive brief

The Sales and Inventory System is a free PHP-based application used by businesses to manage product catalogs and inventory. The vulnerability allows authenticated users to inject malicious SQL queries through a product code parameter, potentially exposing or modifying sensitive database records including product data, prices, and customer information.

Technical details

A SQL injection vulnerability exists in the /pages/pro_edit1.php file where the 'prodcode' parameter is not properly sanitized before being used in SQL queries. An authenticated attacker can inject arbitrary SQL commands through this parameter to manipulate database queries. The attack vector is network-based and requires valid login credentials. Successful exploitation allows attackers to read unauthorized data, modify or delete records, and potentially achieve broader database control. No patch has been disclosed; users should update to a patched version once available or apply input validation and parameterized queries.

Affected products

  • itsourcecode Sales and Inventory System 1.0

Timeline

  • 2026-09-14: disclosed: Vulnerability disclosed and PoC published on GitHub

References