Junglewise Threat Intelligence

CVE-2026-13570: SourceCodester Inventory Management System XSS in User Registration Endpoint

CVE-2026-13570 · Severity: low · CVSS 3.5 · Published 2026-06-29

Technologies: SourceCodester Inventory Management System. Vendors: SourceCodester.

Executive brief

SourceCodester Inventory Management System 1.0 is a web application used for tracking stock and business inventory. A security vulnerability in the user registration component allows an attacker to inject malicious scripts into the system via the 'full_name' field. If an administrative user views the affected data, the attacker could potentially perform unauthorized actions in the context of that user's session.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Inventory Management System 1.0. The flaw is located within the User Registration Endpoint in the /api/users_handler.php file. An attacker can exploit this by manipulating the 'full_name' parameter during registration to include malicious JavaScript. The vulnerability requires low administrative privileges to execute and relies on user interaction (a victim viewing the injected content). Successful exploitation allows for the execution of arbitrary script code in the victim's browser session. A public exploit is reportedly available.

Affected products

  • SourceCodester Inventory Management System 1.0

Timeline

  • 2026-06-29: disclosed: Vulnerability disclosed via VulDB and NVD

References

Related threats