Description
A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument order_date/invoice_no leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Restrict Access
AI Analysis

Impact

A flaw in the invoice generation component of Rizwan17's inventory-management-system allows an attacker to manipulate the order_date and invoice_no parameters in the invoice_bill.php script. This manipulation bypasses the authentication checks for that endpoint, enabling an unauthenticated user to generate invoices and potentially expose transaction data. The vulnerability, which can be exploited remotely, does not directly grant code execution but undermines the integrity and confidentiality of financial records. It originates from a missing authentication guard in a known code path, aligning with CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function).

Affected Systems

The affected product is Rizwan17's inventory-management-system. No specific release or version numbers are available because the project provides rolling releases. The vulnerability is present in all releases up to the commit referenced in the advisory and may exist in newer commits until a fix is released.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. EPSS data is not available and the vulnerability is not cataloged in CISA KEV. The attack can be launched remotely over the internet, and the lack of an authentication requirement makes exploitation straightforward for any unauthenticated user. Given the publicly disclosed exploit, the likelihood of exploitation is non-zero, and the risk is significant for environments where the application is exposed to untrusted networks.

Generated by OpenCVE AI on September 10, 2026 at 00:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enforce authentication on the invoice generation endpoints before processing any parameters so that only verified sessions can trigger invoice creation.
  • Apply the latest release from the vendor when it becomes available or manually patch the missing authentication check in the invoice_bill.php script.
  • Use a web application firewall or request filtering rules to block requests that attempt to invoke invoice generation without proper session cookies or authentication headers.
  • Monitor web server and application logs for repeated attempts to access the invoice generation endpoint without authentication and investigate any anomalies.

Generated by OpenCVE AI on September 10, 2026 at 00:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument order_date/invoice_no leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Title Rizwan17 inventory-management-system Invoice Generation invoice_bill.php missing authentication
First Time appeared Rizwan17
Rizwan17 inventory-management-system
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*
Vendors & Products Rizwan17
Rizwan17 inventory-management-system
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Rizwan17 Inventory-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-10T17:47:51.568Z

Reserved: 2026-09-09T16:11:15.175Z

Link: CVE-2026-87924

cve-icon Vulnrichment

Updated: 2026-09-10T17:47:17.127Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T23:16:56.430

Modified: 2026-09-10T18:18:11.457

Link: CVE-2026-87924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:45:04Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function