MEDIUMVulnerability
CVE-2026-86675
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Properties
- severity
- MEDIUM
- score
- 6.3
- cve_id
- CVE-2026-86675
- signal_observed_at
- 2026-09-16T21:37:30+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- published_at
- 2026-09-08T19:20:17.173
- last_modified
- 2026-09-10T18:18:10.317
Related Entities (3)
HAS_WEAKNESS (2)
→[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
→[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph