Junglewise Threat Intelligence

CVE-2026-90696: SourceCodester Inventory Management System stored XSS in product name

CVE-2026-90696 · Severity: low · CVSS 3.5 · Published 2026-09-14

Technologies: SourceCodester Inventory Management System. Vendors: SourceCodester.

Executive brief

SourceCodester Inventory Management System is a web-based application for managing product inventory. A stored cross-site scripting (XSS) vulnerability in the product name field allows authenticated attackers to inject malicious scripts that execute when any user views the product catalog, enabling session hijacking and account takeover.

Technical details

A stored XSS vulnerability exists in the Product Management module (/api/products_handler.php and /products.php) due to insufficient input sanitization of the Product_Name parameter. The application fails to sanitize or encode user-supplied input before storing it in the database and rendering it on the product catalog page. An authenticated attacker can inject JavaScript code via the Product_Name field, which persists in the database and executes in the browser context of any user viewing the products page, allowing session cookie theft and account takeover. The vulnerability requires authentication but has low preconditions—any authenticated user can inject the payload. No patch information is currently available.

Affected products

  • SourceCodester Inventory Management System 1.0

Timeline

  • 2026-08-05: disclosed
  • 2026-09-14: advisory

References

Related threats