Junglewise Threat Intelligence

CVE-2026-11518: SourceCodester Inventory System stored XSS in User Management Page

CVE-2026-11518 · Severity: medium · CVSS 4.3 · Published 2026-06-08

Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Inventory System 1.0 that allows unauthorized individuals to take control of administrator accounts. By submitting a malicious registration form, an attacker can inject hidden scripts that activate when an administrator views the user management panel. This can lead to the theft of login sessions, unauthorized changes to inventory data, or a complete takeover of the management system.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Inventory System 1.0 due to insufficient input sanitization in the 'register.php' component. An unauthenticated remote attacker can inject arbitrary JavaScript into the 'fullname' and 'username' parameters during the staff registration process. These malicious payloads are stored in the database and subsequently executed in the browser of an administrative user when they visit the 'users.php' management page. Successful exploitation allows for session hijacking via cookie theft, unauthorized administrative actions, or redirection to malicious sites. No patch is currently reported for this version.

Affected products

  • SourceCodester Inventory System 1.0

Timeline

  • 2026-05-23: other: Vulnerability submitted to vendor/publicly documented
  • 2026-06-08: disclosed: CVE published

References