PT-2025-21854 · Unknown · Itsourcecode Sales/Inventory System

0X0A1Lphi

·

Published

2025-05-18

·

Updated

2025-05-18

·

CVE-2025-4886

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iSourcecode Sales and Inventory System version 1.0
Description A critical vulnerability was found in the iSourcecode Sales and Inventory System, affecting an unknown functionality of the file /pages/product update.php. The manipulation of the serial argument leads to SQL injection. The attack can be launched remotely. Other parameters might be affected as well.
Recommendations For iSourcecode Sales and Inventory System version 1.0, consider disabling access to the /pages/product update.php file until a patch is available. As a temporary workaround, restrict the use of the serial argument in the product update.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-4886

Affected Products

Itsourcecode Sales/Inventory System