Description
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_customers.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published: 2026-03-30
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The vulnerability is a reflected Cross‑Site Scripting flaw that permits an attacker to inject malicious script or HTML by manipulating the 'limit' parameter in the view_customers.php page. When a victim opens a URL containing the crafted value, the injected code runs within the victim’s browser session, potentially enabling session hijacking, data theft, or defacement. The weakness is a failure to properly validate and encode user input before rendering, corresponding to the Cross‑Site Scripting category.

Affected Systems

The flaw affects the Sales and Inventory System version 1.0, as identified by the provided product information. No other vendors or product versions are disclosed, so remediation efforts should focus on any installations of this specific edition.

Risk and Exploitability

A CVSS base score of 6.1 indicates moderate severity; the EPSS probability of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to click a malicious link, making the attack client‑side and dependent on user interaction. If successful, the injected script operates within the victim’s browser context and could compromise any data or operations authorized to that session.

Generated by OpenCVE AI on April 2, 2026 at 04:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update the Sales and Inventory System to a version where the 'limit' parameter is properly sanitized
  • Validate and encode all user‑supplied data before outputting it to the browser
  • If a patch is not yet available, disable or restrict access to the functionality that uses the 'limit' parameter until the flaw is fixed

Generated by OpenCVE AI on April 2, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Title Reflected XSS in view_customers.php via 'limit' Parameter

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System
CPEs cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:*
Vendors & Products Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System

Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester sales And Inventory System
Vendors & Products Sourcecodester
Sourcecodester sales And Inventory System

Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Title Reflected XSS in view_customers.php via 'limit' Parameter

Mon, 30 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Description A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_customers.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
References

Subscriptions

Ahsanriaz26gmailcom Sales And Inventory System
Sourcecodester Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-30T15:31:22.779Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30566

cve-icon Vulnrichment

Updated: 2026-03-30T15:31:16.742Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-30T15:16:26.843

Modified: 2026-04-01T17:47:27.347

Link: CVE-2026-30566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T07:54:31Z

Weaknesses