Description
A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been published and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery leading to unauthorized state changes
Action: Patch or Mitigate
AI Analysis

Impact

A flaw in the inventory‑management‑system allows an attacker to perform cross‑site request forgery via an unknown function in includes/process.php. By crafting a malicious request the attacker can trigger state‑changing operations without the victim’s intent, compromising integrity. The flaw is a classic CSRF vulnerability identified as CWE‑352 and also exposes an unauthorized access weakness (CWE‑862).

Affected Systems

The vulnerability affects Rizwan17 inventory‑management‑system, any release before commit 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. Version specifics are not available due to the project's rolling release model; however, any instance running a pre‑patched commit is susceptible.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, yet the exploit is publicly available and can be launched remotely. The vulnerability is not listed in CISA’s KEV catalog, but the public proof‑of‑concept demonstrates that attackers can abuse it. The likely attack vector is a remote crafted request to the vulnerable endpoint, possibly via a malicious link or a web page tricking the user.

Generated by OpenCVE AI on September 15, 2026 at 16:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest update from the project's repository or apply the latest commit that contains the CSRF fix.
  • If an immediate update is not possible, to the process.php endpoint, ensuring the token is required and verified for all state‑changing requests.
  • Enforce proper user authentication and permission checks before processing any operation in process.php to mitigate the unauthorized access weakness.
  • Configure a Web Application Firewall or ruleset to detect and block suspicious state‑changing requests or enforce double‑submit cookies.

Generated by OpenCVE AI on September 15, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been published and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Title Rizwan17 inventory-management-system process.php cross-site request forgery
First Time appeared Rizwan17
Rizwan17 inventory-management-system
Weaknesses CWE-352
CWE-862
CPEs cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:*
Vendors & Products Rizwan17
Rizwan17 inventory-management-system
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Rizwan17 Inventory-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:22:53.835Z

Reserved: 2026-09-12T18:47:29.335Z

Link: CVE-2026-90599

cve-icon Vulnrichment

Updated: 2026-09-14T15:22:49.635Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T22:17:01.053

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90599

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-862

    Missing Authorization