Executive brief
SourceCodester Stock Management System is a web-based application for managing stock and orders. A stored cross-site scripting (XSS) vulnerability in the order report feature allows attackers to inject malicious scripts through order form fields. When an administrator views the generated report, the injected script executes in their browser, enabling theft of session cookies, account takeover, and unauthorized actions on behalf of the victim.
Technical details
A stored XSS vulnerability (CWE-79) exists in /php_action/getOrderReport.php due to insufficient output encoding. User-supplied clientName and clientContact parameters are accepted via /php_action/createOrder.php without sanitization and stored directly in the MySQL database. When the report is generated, these values are output directly into HTML <td> elements without htmlspecialchars() encoding, allowing stored XSS payloads to execute. No authentication is required to inject the payload; any user can create an order with malicious content. The vulnerability affects report generation where administrators view aggregated orders, and triggers when accessing the report page with a date range that includes the malicious order. The exploit has been publicly disclosed.
Affected products
- SourceCodester Stock Management System 1.0
Timeline
- 2026-07-06: disclosed
- 2026-08-23: advisory