THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86234 (MEDIUM 6.3) — A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible to launch the attack remotely. The exploit

[NVD] CVE-2026-86234 (MEDIUM 6.3) — A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible to launch the attack remotely. The exploit

mednvdPublished 2026-09-07

CVE-2026-86234 CVSS: 6.3 MEDIUM Published: 2026-09-07T00:17:46.867

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86234