Description
A security vulnerability has been detected in amirsanni mini-inventory-and-sales-management-system up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. Impacted is an unknown function of the file application/controllers/Items.php of the component Items Management Module. The manipulation of the argument itemName leads to cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Remote Cross‑Site Scripting
Action: Assess Impact
AI Analysis

Impact

A vulnerability has been found in the Items Management module of the amirsanni mini‑inventory‑and‑sales‑management‑system. By manipulating the itemName parameter sent to application/controllers/Items.php, an attacker can inject arbitrary script code that is rendered in the browser of downstream users. The vulnerability is an instance of cross‑site scripting (CWE‑79), and the ability to inject code also implicates dynamic code execution (CWE‑94). Successful exploitation would allow an attacker to execute malicious scripts in the victim's browser, potentially hijacking user sessions, defacing content, or collecting sensitive data from the authenticated session.

Affected Systems

The affected software is the amirsanni mini‑inventory‑and‑sales‑management‑system, version up to commit 81bf0b55f5933f3b0dbb1583204a612e06605b95. The product follows a rolling release approach with continuous delivery, meaning specific version numbers are not published. Therefore, any deployment that has not been updated to a release after the mentioned commit is likely vulnerable.

Risk and Exploitability

The CVSS score is 5.1, indicating a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw is triggered by a user‑controlled request parameter in a publicly accessible web endpoint, the attack vector is remote and does not require authentication. An attacker only needs to craft a malicious itemName value in an HTTP request; no additional prerequisites are mentioned. The presence of CWE‑79 and CWE‑94 suggests that the issue arises from insufficient input validation and execution of untrusted code, which can be relatively easy to exploit in the absence of mitigation.

Generated by OpenCVE AI on September 28, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of the mini‑inventory‑and‑sales‑management‑system once an official patch is released.
  • If an immediate update is not possible, modify the server‑side code that processes the itemName argument to escape or strip dangerous HTML tags and characters before rendering, thereby preventing script injection.
  • Deploy a web application firewall or inline input validation rules that block payloads containing script tags or inline event handlers submitted to the itemName field.
  • Monitor application logs for repeated XSS attempts and review user agent strings for suspicious activity.

Generated by OpenCVE AI on September 28, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in amirsanni mini-inventory-and-sales-management-system up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. Impacted is an unknown function of the file application/controllers/Items.php of the component Items Management Module. The manipulation of the argument itemName leads to cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Title amirsanni mini-inventory-and-sales-management-system Items Management Items.php cross site scripting
First Time appeared Amirsanni
Amirsanni mini-inventory-and-sales-management-system
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:amirsanni:mini-inventory-and-sales-management-system:*:*:*:*:*:*:*:*
Vendors & Products Amirsanni
Amirsanni mini-inventory-and-sales-management-system
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:C'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:C'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Amirsanni Mini-inventory-and-sales-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T03:30:10.816Z

Reserved: 2026-09-27T09:10:47.289Z

Link: CVE-2026-100904

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T04:17:07.910

Modified: 2026-09-28T04:17:07.910

Link: CVE-2026-100904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T04:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')