Executive brief
Rizwan17's inventory management system, a web application for tracking products and orders, lacks anti-CSRF (cross-site request forgery) protections on all state-changing operations. An attacker can trick an authenticated user into unwittingly creating admin accounts, deleting products, or placing fraudulent orders by luring them to a malicious webpage. This allows unauthorized changes to inventory without the victim's knowledge or consent.
Technical details
The vulnerability is a cross-site request forgery (CSRF) in the includes/process.php file affecting all POST endpoints. The root cause is the absence of CSRF token validation and inadequate authentication checks; the application relies solely on session cookies and never binds state-changing requests to a per-session secret token or implements strict Origin/Referer checks. An attacker can craft a malicious HTML form or fetch request that, when visited by an authenticated user, will be automatically submitted with the victim's session credentials attached by the browser. This allows the attacker to perform actions such as deleting products, adding categories, creating user accounts, or placing orders. No patch has been released; the project uses rolling releases and has not yet responded to the early disclosure.
Affected products
- Rizwan17 inventory-management-system up to commit 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2
Timeline
- 2026-09-13: disclosed: CVE-2026-90599 published
- 2026-08-03: other: Vulnerability reported via GitHub issue #17