Description
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handler. This manipulation of the argument category_name/brand_name/product_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side script injection leading to potential session hijacking or defacement
Action: Patch
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw in the List Handler’s DBOperation.php page. By supplying specially crafted values for the category_name, brand_name, or product_name parameters, an attacker can inject arbitrary JavaScript that will execute in the browser of any user who loads the affected page. This leads to the possibility of session hijacking, data theft, or defacement of the application from the victim’s perspective.

Affected Systems

The flaw exists in Rizwan17 inventory‑management‑system across all releases before commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. The component in question is the List Handler within the includes/DBOperation.php file. Because the project follows a rolling release model, specific version numbers for affected code are not available, but all instances of this file before the aforementioned commit are affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploitation requires the user to be directed to a URL containing the malicious parameters, meaning the attack vector is remote through crafted links. As the exploit code has been published publicly, attackers could readily leverage it against any installation of the system that has not been updated to the fixed commit.

Generated by OpenCVE AI on September 9, 2026 at 23:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest release of the inventory‑management‑system that contains the commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f or later.
  • Implement input validation and output encoding for the category_name, brand_name, and product_name parameters in DBOperation.php to prevent reflected XSS.
  • Configure a robust Content Security Policy and set HTTP security headers to mitigate the impact of any residual XSS attempts.

Generated by OpenCVE AI on September 9, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handler. This manipulation of the argument category_name/brand_name/product_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title Rizwan17 inventory-management-system List DBOperation.php cross site scripting
First Time appeared Rizwan17
Rizwan17 inventory-management-system
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*
Vendors & Products Rizwan17
Rizwan17 inventory-management-system
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Rizwan17 Inventory-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:33:50.718Z

Reserved: 2026-09-09T16:11:11.898Z

Link: CVE-2026-87923

cve-icon Vulnrichment

Updated: 2026-09-11T20:02:41.104Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T23:16:56.253

Modified: 2026-09-11T21:17:51.387

Link: CVE-2026-87923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T14:15:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')