Impact
The vulnerability is a client‑side cross‑site scripting flaw in Version 1.0 of the Product Management Module. Manipulating the Product_Name argument in /api/products_handler.php injects malicious script into the response page, allowing an attacker to run arbitrary JavaScript within the victim’s browser. This flaw is associated with CWE‑79 and involves unsafe evaluation of input as indicated by CWE‑94.
Affected Systems
The affected product is SourceCodester’s Inventory Management System, version 1.0, specifically the Product Management Module that exposes /api/products_handler.php. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.1 denotes moderate severity, while the EPSS of less than 1 % reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit this flaw remotely by sending a crafted request to /api/products_handler.php with a malicious Product_Name value that the page subsequently reflects, enabling session hijacking, phishing, or other malicious client‑side actions.
OpenCVE Enrichment