Junglewise Threat Intelligence

CVE-2026-78059: SourceCodester Stock Management System stored XSS in printOrder.php

CVE-2026-78059 · Severity: medium · CVSS 4.3 · Published 2026-08-23

Vendors: SourceCodester.

Executive brief

SourceCodester Stock Management System is a web-based application for managing inventory orders. A stored cross-site scripting (XSS) vulnerability in the order management feature allows attackers to inject malicious scripts through order creation fields (client name and contact), which are then executed when administrators view print orders. An attacker can steal session tokens, impersonate users, deface pages, or redirect users to malicious sites without authentication.

Technical details

A stored XSS vulnerability exists in the Stock Management System due to insufficient input sanitization in php_action/createOrder.php and lack of output encoding in php_action/printOrder.php. User-supplied clientName and clientContact parameters are inserted into the database without sanitization, then retrieved and rendered directly into HTML without htmlspecialchars() or equivalent encoding. The vulnerability is remotely exploitable without authentication—an attacker can create an order with JavaScript payload in the client name field, and the payload executes whenever an authenticated user views the print order page. Patches are available through input validation/filtering and output encoding as described in the advisory.

Affected products

  • SourceCodester Stock Management System 1.0

Timeline

  • 2026-07-06: disclosed: Vulnerability reported to GitHub
  • 2026-08-23: advisory: CVE-2026-78059 published

References

Related threats