Impact
A flaw exists in SourceCodester Inventory Management System 1.0 that allows an attacker to inject malicious script code through the vendors_handler.php API endpoint. The vulnerability is a reflected cross‑site scripting condition that can be triggered remotely by supplying forged input. When a legitimate user visits a crafted URL, the browser executes the injected script within the context of the web application, potentially stealing session cookies, defacing content, or executing further malicious actions.
Affected Systems
The source of the issue is SourceCodester Inventory Management System 1.0, specifically the Vendor Management component exposed via the /api/vendors_handler.php file.
Risk and Exploitability
The CVSS score of 5.1 places the flaw in the moderate range, and the EPSS score of less than 1% indicates a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, but the exploit has been made public, meaning a capable adversary could construct attacks remotely using standard browser payloads. Consequently, the primary risk is to user sessions and data integrity for users who interact with the affected endpoint.
OpenCVE Enrichment