Executive brief
A security flaw in the SourceCodester Inventory System allows users to bypass intended permission levels. By manipulating account creation settings, a remote attacker can assign themselves or others unauthorized roles, potentially gaining administrative access to the inventory management platform. This could lead to unauthorized data modification or full system takeover.
Technical details
An improper authorization vulnerability (CWE-285/CWE-266) exists in SourceCodester Inventory System 1.0 within the file /Product_Inventory/api/users_handler.php. The 'Account Creation Handler' component fails to properly validate the 'ROLE' argument during user creation or modification. A remote attacker with low-level privileges can manipulate this parameter to escalate privileges or assign unauthorized roles. Public exploit code has been released, increasing the risk of exploitation. No official patch is currently documented in the advisory.
Affected products
- SourceCodester Inventory System 1.0
Timeline
- 2026-06-08: disclosed
- 2026-06-08: advisory