Cross-Site Scripting Vulnerability in SourceCodester Stock Management System
CVE-2026-78060
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 23 August 2026
Badges
What is CVE-2026-78060?
A significant cross-site scripting vulnerability has been detected in the SourceCodester Stock Management System, specifically affecting the file /php_action/getOrderReport.php. This flaw allows attackers to manipulate the parameters clientName and clientContact to inject malicious scripts. The vulnerability is remotely exploitable, raising concerns about potential unauthorized access and data theft. Immediate action is advised to mitigate this risk to safeguard sensitive information.
Affected Version(s)
Stock Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
