Impact
A vulnerability has been found in the Items Management module of the amirsanni mini‑inventory‑and‑sales‑management‑system. By manipulating the itemName parameter sent to application/controllers/Items.php, an attacker can inject arbitrary script code that is rendered in the browser of downstream users. The vulnerability is an instance of cross‑site scripting (CWE‑79), and the ability to inject code also implicates dynamic code execution (CWE‑94). Successful exploitation would allow an attacker to execute malicious scripts in the victim's browser, potentially hijacking user sessions, defacing content, or collecting sensitive data from the authenticated session.
Affected Systems
The affected software is the amirsanni mini‑inventory‑and‑sales‑management‑system, version up to commit 81bf0b55f5933f3b0dbb1583204a612e06605b95. The product follows a rolling release approach with continuous delivery, meaning specific version numbers are not published. Therefore, any deployment that has not been updated to a release after the mentioned commit is likely vulnerable.
Risk and Exploitability
The CVSS score is 5.1, indicating a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw is triggered by a user‑controlled request parameter in a publicly accessible web endpoint, the attack vector is remote and does not require authentication. An attacker only needs to craft a malicious itemName value in an HTTP request; no additional prerequisites are mentioned. The presence of CWE‑79 and CWE‑94 suggests that the issue arises from insufficient input validation and execution of untrusted code, which can be relatively easy to exploit in the absence of mitigation.
OpenCVE Enrichment