MEDIUM

CVE-2026-90600

2026-09-13 CVSS v3.1
CVSS
6.3

Description

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Weakness (CWE)

CWE-74 Injection
CWE-89 SQL Injection

EPSS Score

0.2%
Probability of exploitation in next 30 days
10.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE