Description
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_supplier.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published: 2026-03-30
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑Side Script Injection
Action: Patch Now
AI Analysis

Impact

A reflected Cross‑Site Scripting vulnerability exists in the view_supplier.php component of SourceCodester Sales and Inventory System 1.0. The application does not sanitize the 'limit' parameter, allowing remote attackers to embed arbitrary web script or HTML into a crafted URL. When a user loads the page, the injected code executes in their browser.

Affected Systems

The affected product is SourceCodester Sales and Inventory System version 1.0. No other versions or products are mentioned, and the version is identified by the provided CPE.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity, while the EPSS score below 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote web request containing a malicious payload in the 'limit' parameter; a victim who accesses the crafted link will have the script executed in their browser. No additional prerequisites are required beyond user interaction with the URL.

Generated by OpenCVE AI on April 2, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade to the latest version of SourceCodester Sales and Inventory System that includes input sanitization for the 'limit' parameter.
  • If a patch is not available, enforce server‑side validation to allow only numeric values for the 'limit' parameter.
  • Encode or escape the 'limit' value before rendering it in an HTML context.
  • Deploy a Content Security Policy header that restricts script execution to trusted sources.
  • Consider disabling or removing the 'limit' functionality if it is not required, to reduce the attack surface.

Generated by OpenCVE AI on April 2, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Title Reflected Cross‑Site Scripting via 'limit' Parameter in View Supplier

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System
CPEs cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*
Vendors & Products Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System

Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester sales And Inventory System
Vendors & Products Sourcecodester
Sourcecodester sales And Inventory System

Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Title Reflected Cross‑Site Scripting via 'limit' Parameter in View Supplier

Mon, 30 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Description A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_supplier.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
References

Subscriptions

Ahsanriaz26gmailcom Sales And Inventory System
Sourcecodester Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-30T15:30:34.724Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30565

cve-icon Vulnrichment

Updated: 2026-03-30T15:30:29.871Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-30T15:16:26.710

Modified: 2026-04-01T17:47:15.440

Link: CVE-2026-30565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T07:54:32Z

Weaknesses