Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Title | itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection | |
| First Time appeared |
Itsourcecode
Itsourcecode sales And Inventory System |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:itsourcecode:sales_and_inventory_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Itsourcecode
Itsourcecode sales And Inventory System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-08T03:30:08.615Z
Reserved: 2026-09-07T19:25:26.623Z
Link: CVE-2026-86517
No data.
Status : Received
Published: 2026-09-08T04:17:42.307
Modified: 2026-09-08T04:17:42.307
Link: CVE-2026-86517
No data.
OpenCVE Enrichment
No data.