CVE-2026-90525
Last modified
CVE-2026-90525 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php.
Description
A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| itsourcecode | Sales and Inventory System | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90525?
How severe is CVE-2026-90525?
How do I fix CVE-2026-90525?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9052Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-90520A vulnerability has been found in jaychouchannel Tourism-Man…6.3
- CVE-2026-90521A vulnerability was found in jaychouchannel Tourism-Manageme…6.3
- CVE-2026-90522A vulnerability was determined in jaychouchannel Tourism-Man…7.3
- CVE-2026-90523A vulnerability was identified in jaychouchannel Tourism-Man…7.3
- CVE-2026-90524A security flaw has been discovered in jaychouchannel Touris…7.3
- CVE-2026-90526A security vulnerability has been detected in SourceCodester…7.3
- CVE-2026-9053Mothra would respect a default value given by a website for …6.9
- CVE-2026-90533Flowise before 3.1.4 contains a broken access control vulner…6
- CVE-2026-90534Flowise is a low-code platform for building LLM applications…6.1
- CVE-2026-90535Flowise versions before 3.1.4 contain an unauthenticated den…6.3
- CVE-2026-90536WWBN AVideo through commit c3edcc274c389816d434acadac07ee78e…5.3
Are you affected by CVE-2026-90525?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
