Description
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Monitor
AI Analysis

Impact

The vulnerability is an improper access control flaw in the dashboard.php file of Rizwan17 inventory‑management‑system. By manipulating the userid argument, an attacker can bypass the normal authorization checks and view or modify dashboard data that should be restricted, without executing arbitrary code. The flaw is identified as CWE‑266 and CWE‑284, indicating a weakness in privilege control and access control implementation.

Affected Systems

The affected product is Rizwan17:inventory‑management‑system, a rolling‑release web application. All releases up to the commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f are vulnerable. The project does not publish discrete version numbers and has not released a fixed build; the maintainers have not yet responded to the issue report.

Risk and Exploitability

The CVSS score is 6.9, indicating moderate severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild. Nevertheless, the exploit code is publicly available and the vulnerability can be triggered remotely, providing a tangible threat to exposed installations. The risk lies primarily in unauthorized data exposure and potential data tampering within the dashboard interface. Administrators should treat this as a priority until an official fix is issued or a temporary mitigation is applied.

Generated by OpenCVE AI on September 15, 2026 at 16:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the project's repository or vendor site for any updated release containing a fix; if an updated version exists, deploy it promptly.
  • Restrict remote access to dashboard.php by enforcing proper authentication, validating userid against the authenticated session, and rejecting requests that do not match the current user context.
  • If an update is not feasible, implement a temporary workaround by preventing unauthorized parameter values from being processed, and monitor for further updates or security advisories.

Generated by OpenCVE AI on September 15, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title Rizwan17 inventory-management-system dashboard.php access control
First Time appeared Rizwan17
Rizwan17 inventory-management-system
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*
Vendors & Products Rizwan17
Rizwan17 inventory-management-system
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Rizwan17 Inventory-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:11:38.592Z

Reserved: 2026-09-12T15:51:43.807Z

Link: CVE-2026-90565

cve-icon Vulnrichment

Updated: 2026-09-16T14:11:34.134Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T16:16:52.507

Modified: 2026-09-16T15:18:29.997

Link: CVE-2026-90565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control