MEDIUM
CVE-2026-90600
CVSS
6.3
Description
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Weakness (CWE)
CWE-74
Injection
CWE-89
SQL Injection
EPSS Score
0.2%
Probability of exploitation in next 30 days
10.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.