Executive brief
SourceCodester Inventory Management System 1.0 contains a security flaw in its user registration process. This vulnerability allows an attacker to manipulate their assigned role during registration, potentially gaining unauthorized administrative access to the system. This could lead to the exposure of sensitive inventory data or unauthorized changes to business records.
Technical details
An improper access control vulnerability (CWE-284/CWE-266) exists in SourceCodester Inventory Management System 1.0 within the '/api/users_handler.php' file. The 'User Registration Endpoint' fails to properly validate or restrict the 'role' argument during account creation. A remote, unauthenticated attacker can exploit this by submitting a crafted registration request to assign themselves elevated privileges (such as an administrator role). Public exploit code has been released for this vulnerability.
Affected products
- SourceCodester Inventory Management System 1.0
Timeline
- 2026-06-29: disclosed
- 2026-06-29: advisory