← Terug naar overzicht

A SQL injection vulnerability has been identified in itsourcecode Sales and Inventory System version 1.0. The vulnerability exists in the file /pages/processlogin.php, where manipulation of the 'User' argument allows an attacker to perform SQL injection attacks. The attack can be initiated remotely without requiring physical access to the target system. The exploit has been publicly disclosed and is available for use by malicious actors. This vulnerability poses a significant risk as it could allow unauthorized access to the underlying database. The affected product is a widely used open-source sales and inventory management system. No patch or mitigation details are currently noted in the article.

Affected products

  • itsourcecode Sales and Inventory System 1.0

Related CVE's

  • CVE-2026-78171

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies