Description
A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipulation of the argument Product_Name can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply patch
AI Analysis

Impact

The vulnerability is a client‑side cross‑site scripting flaw in Version 1.0 of the Product Management Module. Manipulating the Product_Name argument in /api/products_handler.php injects malicious script into the response page, allowing an attacker to run arbitrary JavaScript within the victim’s browser. This flaw is associated with CWE‑79 and involves unsafe evaluation of input as indicated by CWE‑94.

Affected Systems

The affected product is SourceCodester’s Inventory Management System, version 1.0, specifically the Product Management Module that exposes /api/products_handler.php. No other versions are listed as affected.

Risk and Exploitability

The CVSS score of 5.1 denotes moderate severity, while the EPSS of less than 1 % reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit this flaw remotely by sending a crafted request to /api/products_handler.php with a malicious Product_Name value that the page subsequently reflects, enabling session hijacking, phishing, or other malicious client‑side actions.

Generated by OpenCVE AI on September 15, 2026 at 14:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s latest security patch for Inventory Management System.
  • Sanitize the Product_Name input or encode output before rendering on the page.
  • Deploy a web application firewall that blocks XSS payloads.
  • Enforce a strict Content Security Policy for all pages.

Generated by OpenCVE AI on September 15, 2026 at 14:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipulation of the argument Product_Name can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester Inventory Management System Product Management products_handler.php cross site scripting
First Time appeared Sourcecodester
Sourcecodester inventory Management System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:sourcecodester:inventory_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester inventory Management System
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Inventory Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T14:38:47.453Z

Reserved: 2026-09-13T05:14:33.906Z

Link: CVE-2026-90696

cve-icon Vulnrichment

Updated: 2026-09-14T14:38:42.916Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T09:17:01.950

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')