Executive brief
Rizwan17's inventory management system is a web application used to manage product orders and generate invoices. An attacker can remotely create forged invoices and write arbitrary files without logging in, allowing them to damage business records and potentially manipulate files on the server.
Technical details
The vulnerability is a missing authentication flaw in the invoice_bill.php component. The endpoint accepts all invoice and order data (customer name, line items, amounts, invoice number) directly from unsanitized GET parameters without any server-side session validation. An unauthenticated attacker can send a crafted HTTP request to generate a malicious PDF invoice and write it to the filesystem with an attacker-controlled filename, including potential path traversal payloads. The invoice_no parameter is concatenated directly into the output filename without sanitization, enabling arbitrary file writes. No patch has been released; the project maintainer has not responded to the early disclosure.
Affected products
- Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
Timeline
- 2026-07-30: disclosed: Vulnerability publicly disclosed via GitHub issue #14
- 2026-09-09: advisory: CVE-2026-87924 published