Junglewise Threat Intelligence

CVE-2026-87923: Rizwan17 inventory-management-system stored cross-site scripting

CVE-2026-87923 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Rizwan17 Inventory Management System.

Executive brief

An open-source inventory management application fails to encode user-supplied product, category, and brand names before displaying them in HTML. An attacker can remotely inject malicious scripts through these fields without authentication, which are then executed in the browsers of legitimate users viewing the management interface, potentially allowing session theft or unauthorized administrative actions.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the List Handler component (includes/DBOperation.php and includes/process.php) of the inventory management system. The vulnerability stems from missing output encoding when displaying inventory names (category_name, brand_name, product_name) in HTML table cells and option labels. User input submitted via unauthenticated POST endpoints is stored in the database without sanitization and later rendered directly into HTML without htmlspecialchars() or equivalent encoding. An attacker can craft a malicious payload (e.g., <script>alert(/XSS/)</script>) and submit it through the brand/category/product creation endpoints, which are accessible without authentication. When legitimate users load the management interface, the malicious script executes in their browser context, enabling session hijacking or administrative impersonation.

Affected products

  • Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

Timeline

  • 2026-07-30: disclosed: Vulnerability reported via GitHub issue #12
  • 2026-09-09: advisory: CVE-2026-87923 published

References