Description
A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (remote)
Action: Assess Impact
AI Analysis

Impact

A flaw exists in SourceCodester Inventory Management System 1.0 that allows an attacker to inject malicious script code through the vendors_handler.php API endpoint. The vulnerability is a reflected cross‑site scripting condition that can be triggered remotely by supplying forged input. When a legitimate user visits a crafted URL, the browser executes the injected script within the context of the web application, potentially stealing session cookies, defacing content, or executing further malicious actions.

Affected Systems

The source of the issue is SourceCodester Inventory Management System 1.0, specifically the Vendor Management component exposed via the /api/vendors_handler.php file.

Risk and Exploitability

The CVSS score of 5.1 places the flaw in the moderate range, and the EPSS score of less than 1% indicates a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, but the exploit has been made public, meaning a capable adversary could construct attacks remotely using standard browser payloads. Consequently, the primary risk is to user sessions and data integrity for users who interact with the affected endpoint.

Generated by OpenCVE AI on September 15, 2026 at 14:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Implement input validation and output encoding for all data processed by vendors_handler.php to neutralize script injection attempts.
  • Apply the latest released version of SourceCodester Inventory Management System if available, or otherwise apply a vendor‑sourced patch if one is released.
  • Deploy a web application firewall with rules targeting cross‑site scripting payloads and configure a strong content security policy to limit script execution domains.

Generated by OpenCVE AI on September 15, 2026 at 14:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Title SourceCodester Inventory Management System Vendor Management vendors_handler.php cross site scripting
First Time appeared Sourcecodester
Sourcecodester inventory Management System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:sourcecodester:inventory_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester inventory Management System
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Inventory Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:49:33.249Z

Reserved: 2026-09-13T05:14:30.666Z

Link: CVE-2026-90695

cve-icon Vulnrichment

Updated: 2026-09-16T14:49:27.539Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T08:16:36.017

Modified: 2026-09-16T15:18:39.640

Link: CVE-2026-90695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')