Junglewise Threat Intelligence

CVE-2026-90599: Rizwan17 inventory-management-system CSRF in process.php

CVE-2026-90599 · Severity: medium · CVSS 4.3 · Published 2026-09-13

Technologies: Rizwan17 Inventory Management System.

Executive brief

Rizwan17's inventory management system, a web application for tracking products and orders, lacks anti-CSRF (cross-site request forgery) protections on all state-changing operations. An attacker can trick an authenticated user into unwittingly creating admin accounts, deleting products, or placing fraudulent orders by luring them to a malicious webpage. This allows unauthorized changes to inventory without the victim's knowledge or consent.

Technical details

The vulnerability is a cross-site request forgery (CSRF) in the includes/process.php file affecting all POST endpoints. The root cause is the absence of CSRF token validation and inadequate authentication checks; the application relies solely on session cookies and never binds state-changing requests to a per-session secret token or implements strict Origin/Referer checks. An attacker can craft a malicious HTML form or fetch request that, when visited by an authenticated user, will be automatically submitted with the victim's session credentials attached by the browser. This allows the attacker to perform actions such as deleting products, adding categories, creating user accounts, or placing orders. No patch has been released; the project uses rolling releases and has not yet responded to the early disclosure.

Affected products

  • Rizwan17 inventory-management-system up to commit 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2

Timeline

  • 2026-09-13: disclosed: CVE-2026-90599 published
  • 2026-08-03: other: Vulnerability reported via GitHub issue #17

References