在 SourceCodester 库存管理系统 1.0 中发现了一个漏洞。该漏洞影响产品管理模块中 /api/products_handler.php 文件的某个未知功能。通过操纵 Product_Name 参数,攻击者可以引发跨站脚本(XSS)攻击。该攻击可以从远程发起。此漏洞的利用方式已公开披露,并可能被实际利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Inventory Management System | 1.0 |
cpe:2.3:a:sourcecodester:inventory_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90697 | 4.3 MEDIUM | SourceCodester Inventory Management System invoice.php authorization |
| CVE-2026-90615 | 4.3 MEDIUM | SourceCodester Class and Exam Timetabling System subject1.php cross site scripting |
| CVE-2026-90695 | 3.5 LOW | SourceCodester Inventory Management System Vendor Management vendors_handler.php cross sit |
| CVE-2026-90694 | 3.5 LOW | SourceCodester Inventory Management System Customer Management customers_handler.php cross |
No comments yet