SQL Injection Vulnerability in itsourcecode Sales and Inventory System
CVE-2026-90525
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 13 September 2026
Badges
What is CVE-2026-90525?
A vulnerability exists in the itsourcecode Sales and Inventory System version 1.0 that allows for SQL injection through improper handling of the 'firstname' argument in the /pages/cust_pos_trans.php file. Attackers can leverage this weakness to execute unauthorized commands on the database, potentially compromising sensitive information. This exploit, which can be initiated remotely, has been publicly disclosed, raising concerns for users relying on this application for managing sales and inventory. It's crucial for organizations using this system to apply appropriate security measures to mitigate potential risks.
Affected Version(s)
Sales and Inventory System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
