Junglewise Threat Intelligence

CVE-2026-9414: SourceCodester Indian Invoicing System stored XSS in add_order.php

CVE-2026-9414 · Severity: low · CVSS 3.5 · Published 2026-05-25

Technologies: SourceCodester Indian Invoicing System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Indian Invoicing System, a web application used for managing business invoices. An attacker can inject malicious scripts into customer name fields, which are then executed in the browsers of other users, such as staff or administrators, when they view the affected invoices. This could lead to unauthorized actions being performed in the context of the victim's session or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Indian Invoicing System up to version 1.0. The root cause is the failure of the application to perform output encoding when rendering database-backed values in the invoice templates located in /Invoice.php and /IGST_Invoice.php. A remote attacker with low privileges can submit a malicious payload via the 'customer_name' parameter in a POST request to /Invoicing/add_order.php. When an authenticated user views the rendered invoice, the injected JavaScript executes in their browser context. This can be used to hijack sessions or perform unauthorized actions on behalf of the victim. Public exploit code (PoC) is available.

Affected products

  • SourceCodester Indian Invoicing System 0.x/1.0

Timeline

  • 2026-04-26: other: Vulnerability discovered and PoC created by researcher
  • 2026-05-25: advisory: Initial disclosure date

References

Related threats