← Terug naar overzicht

A SQL injection vulnerability has been identified in itsourcecode Sales and Inventory System version 1.0. The vulnerability exists in the file /pages/processlogin.php, where manipulation of the 'User' argument allows an attacker to perform SQL injection. The attack can be initiated remotely without requiring physical access to the system. The exploit has been publicly disclosed and is available for use, increasing the risk of exploitation. This vulnerability poses a significant risk to organizations using this software, as it could allow attackers to access, modify, or delete database contents. The affected product is a sales and inventory management system commonly used by small businesses. No patch or mitigation details are mentioned in the article. The vulnerability has been catalogued in VulDB and NVD databases.

Affected products

  • itsourcecode Sales and Inventory System 1.0

Related CVE's

  • CVE-2026-78171

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies