SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82421

MEDIUM · CVSS 6.3 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A SQL injection vulnerability exists in the emp_edit.php file of the itsourcecode Sales and Inventory System 1.0, allowing attackers to manipulate the ID argument and execute unauthorized SQL commands. This issue can be exploited remotely, posing a risk of data exposure or manipulation. Organizations using this system should prioritize remediation to mitigate potential data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82421
Severity
MEDIUM
CVSS
6.3
EPSS
0.20%

Original NVD Description

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/emp_edit.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.