在 SourceCodester 库存管理系统 1.0 中发现一个漏洞。受影响的是客户管理模块中 /api/customers_handler.php 文件的某个未知函数。对参数 Customer_Name 的特定操作会导致跨站脚本攻击(XSS)。该攻击可被远程执行。相关漏洞详情已公开披露,且可能已被利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Inventory Management System | 1.0 |
cpe:2.3:a:sourcecodester:inventory_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90697 | 4.3 MEDIUM | SourceCodester Inventory Management System invoice.php authorization |
| CVE-2026-90615 | 4.3 MEDIUM | SourceCodester Class and Exam Timetabling System subject1.php cross site scripting |
| CVE-2026-90696 | 3.5 LOW | SourceCodester Inventory Management System Product Management products_handler.php cross s |
| CVE-2026-90695 | 3.5 LOW | SourceCodester Inventory Management System Vendor Management vendors_handler.php cross sit |
No comments yet