Description
A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting via the msg parameter
Action: Mitigate
AI Analysis

Impact

The vulnerability exists in the index.php login page of the Rizwan17 inventory‑management‑system. The msg query argument is concatenated into the response without proper sanitization, allowing an attacker to inject arbitrary JavaScript. A successful exploitation can lead to the execution of malicious scripts in the browsers of users who view the affected page, potentially resulting in session hijacking or defacement.

Affected Systems

The product affected is the Rizwan17 inventory‑management‑system. No version information is available because the project does not maintain releases, but all instances running code prior to the commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f are vulnerable. The vulnerability pertains to the Login Page component, specifically the index.php file.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely and an exploit has already been published, so an attacker could target any exposed instance. The impact is observed when a user visits the login page and processes the reflected msg parameter, which can result in arbitrary client‑side script execution. The lack of an official patch means that the vulnerability must be addressed manually or through community‑provided fixes.

Generated by OpenCVE AI on September 10, 2026 at 01:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the repository for an updated commit that removes the unsanitized echo of the msg parameter; apply that commit as a patch.
  • Implement input validation or sanitization for the msg query argument on the login page—e.g., encode HTML entities or use a whitelist of allowed characters before echoing.
  • Configure the web server to block or ignore the msg parameter, or redirect users to a login form that does not reflect user input.

Generated by OpenCVE AI on September 10, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Title Rizwan17 inventory-management-system Login Page index.php cross site scripting
First Time appeared Rizwan17
Rizwan17 inventory-management-system
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*
Vendors & Products Rizwan17
Rizwan17 inventory-management-system
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Rizwan17 Inventory-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T18:41:17.991Z

Reserved: 2026-09-09T16:11:21.718Z

Link: CVE-2026-87926

cve-icon Vulnrichment

Updated: 2026-09-14T18:41:14.439Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T00:17:24.567

Modified: 2026-09-14T19:17:53.500

Link: CVE-2026-87926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')