PT-2026-47292 · Sourcecodester · Sourcecodester Inventory System
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Inventory System version 1.0
Description
Cross site scripting can be triggered remotely via the User Management Page component in the file '/users.php'. The issue occurs through the manipulation of the
fullname or username arguments.Recommendations
Update SourceCodester Inventory System to a version newer than 1.0. As a temporary workaround, restrict access to the '/users.php' file or the User Management Page to minimize the risk of exploitation.
Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecodester Inventory System