Executive brief
SourceCodester Inventory Management System is a web-based application used to manage product inventory and vendor information. A stored cross-site scripting (XSS) vulnerability in the Vendor Management module allows authenticated attackers to inject malicious JavaScript into vendor records, which then executes in the browsers of any user who views the vendor list—including administrators. This can lead to session hijacking, account takeover, and unauthorized access to sensitive inventory data.
Technical details
The vulnerability is a stored cross-site scripting (CWE-79) flaw in the /api/vendors_handler.php and /vendors.php components. The Vendor Management module fails to sanitize or validate user input in vendor fields (name, mobile, email, address, PAN, GST) before storing them in the database or rendering them in the HTML response. An authenticated attacker can inject JavaScript payloads via the vendor creation endpoint; the malicious script is persisted in the database and executed whenever any authenticated user views the vendor list page. The attack requires authentication but enables session cookie theft and account takeover of any user, including administrators. Input validation and output encoding via htmlspecialchars() or similar functions are required to fix this issue.
Affected products
- SourceCodester Inventory Management System 1.0
Timeline
- 2026-08-05: disclosed
- 2026-09-14: advisory