在 itsourcecode 销售和库存管理系统 1.0 中检测到一处安全漏洞。受影响的元素是文件 /pages/sup_edit1.php 中的一个未知函数。对参数 ID 的操纵会导致 SQL 注入。攻击可能从远程发起。该漏洞的利用方式已经公开披露,且可能被利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Sales and Inventory System | 1.0 |
cpe:2.3:a:itsourcecode:sales_and_inventory_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90525 | 6.3 MEDIUM | itsourcecode Sales and Inventory System cust_pos_trans.php sql injection |
| CVE-2026-90574 | 6.3 MEDIUM | itsourcecode Sales and Inventory System emp_transac.php add sql injection |
| CVE-2026-90600 | 6.3 MEDIUM | itsourcecode Sales and Inventory System inv_edit1.php sql injection |
No comments yet