Impact
The vulnerability exists in the index.php login page of the Rizwan17 inventory‑management‑system. The msg query argument is concatenated into the response without proper sanitization, allowing an attacker to inject arbitrary JavaScript. A successful exploitation can lead to the execution of malicious scripts in the browsers of users who view the affected page, potentially resulting in session hijacking or defacement.
Affected Systems
The product affected is the Rizwan17 inventory‑management‑system. No version information is available because the project does not maintain releases, but all instances running code prior to the commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f are vulnerable. The vulnerability pertains to the Login Page component, specifically the index.php file.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely and an exploit has already been published, so an attacker could target any exposed instance. The impact is observed when a user visits the login page and processes the reflected msg parameter, which can result in arbitrary client‑side script execution. The lack of an official patch means that the vulnerability must be addressed manually or through community‑provided fixes.
OpenCVE Enrichment