Junglewise Threat Intelligence

CVE-2026-90565: Rizwan17 inventory-management-system auth bypass in dashboard.php

CVE-2026-90565 · Severity: medium · CVSS 5.3 · Published 2026-09-13

Technologies: Rizwan17 Inventory Management System.

Executive brief

Rizwan17's inventory-management-system is an open-source application for managing product inventory and orders. An authentication bypass flaw allows unauthenticated attackers to access protected pages and retrieve sensitive information (internal UI structure, database records) by exploiting incomplete session checks that redirect but do not stop page execution. The vulnerability could enable attackers to perform unauthorized inventory modifications or access confidential operational data.

Technical details

The vulnerability is an improper access control flaw in dashboard.php and related protected pages. When an unauthenticated request arrives, the application emits a Location header redirect but does not exit execution, causing PHP to continue rendering the protected page body. Non-browser HTTP clients (e.g., curl, automated tools) receive both the redirect header and full protected content without requiring a valid session cookie. The attack is network-accessible, requires no authentication or user interaction, and allows disclosure of internal UI elements and form endpoints. The root cause is missing exit() or return statements after the header() redirect call. The project has not yet patched this issue as of the advisory publication date.

Affected products

  • Rizwan17 inventory-management-system up to commit bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

Timeline

  • 2026-09-13: disclosed: Published on NVD
  • 2026-08-01: other: Issue reported on GitHub

References