Impact
The vulnerability is a cross‑site scripting flaw in the List Handler’s DBOperation.php page. By supplying specially crafted values for the category_name, brand_name, or product_name parameters, an attacker can inject arbitrary JavaScript that will execute in the browser of any user who loads the affected page. This leads to the possibility of session hijacking, data theft, or defacement of the application from the victim’s perspective.
Affected Systems
The flaw exists in Rizwan17 inventory‑management‑system across all releases before commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. The component in question is the List Handler within the includes/DBOperation.php file. Because the project follows a rolling release model, specific version numbers for affected code are not available, but all instances of this file before the aforementioned commit are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploitation requires the user to be directed to a URL containing the malicious parameters, meaning the attack vector is remote through crafted links. As the exploit code has been published publicly, attackers could readily leverage it against any installation of the system that has not been updated to the fixed commit.
OpenCVE Enrichment