Description
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published: 2026-03-30
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Patch Immediately
AI Analysis

Impact

A reflected XSS flaw in the view_payments.php page permits attackers to inject arbitrary JavaScript or HTML through the unsanitized limit query parameter. The injected payload can execute in the victim’s browser, enabling session hijacking, credential theft, and defacement of the application, corresponding to CWE‑79.

Affected Systems

The vulnerability affects SourceCodester Sales and Inventory System version 1.0, as identified by the provided CPE string.

Risk and Exploitability

With a CVSS score of 6.1 the flaw presents moderate severity, while the EPSS score of less than 1 % indicates a low likelihood of current exploitation. The bug is not listed in the CISA KEV catalog. Likely exploitation requires a remote attacker to craft a malicious URL containing the limit parameter and lure or force a legitimate user to visit it, resulting in the execution of the injected script.

Generated by OpenCVE AI on April 2, 2026 at 03:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied patch or upgrade to a newer version of the Sales and Inventory System.
  • If an update is unavailable, modify the application to properly validate or encode the limit parameter before rendering it.
  • Implement a content‑security policy to restrict allowable script sources.
  • Deploy a web‑application firewall rule set to block or neutralize reflected XSS payloads.

Generated by OpenCVE AI on April 2, 2026 at 03:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester sales And Inventory System
Vendors & Products Sourcecodester
Sourcecodester sales And Inventory System

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Title Reflected XSS via Unsanitized 'limit' Parameter in SourceCodester Sales and Inventory System 1.0

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System
CPEs cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*
Vendors & Products Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System

Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Title Reflected XSS via Unsanitized 'limit' Parameter in SourceCodester Sales and Inventory System 1.0

Mon, 30 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Description A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
References

Subscriptions

Ahsanriaz26gmailcom Sales And Inventory System
Sourcecodester Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-30T15:29:45.380Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30564

cve-icon Vulnrichment

Updated: 2026-03-30T15:29:37.800Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-30T15:16:26.590

Modified: 2026-04-01T17:46:39.120

Link: CVE-2026-30564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-03T09:11:42Z

Weaknesses