Cross-Site Scripting Vulnerability in Code-Projects Simple Inventory System
CVE-2026-82625
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 31 August 2026
Badges
What is CVE-2026-82625?
A cross-site scripting vulnerability has been identified in the Simple Inventory System 1.0 that affects the /register.php file associated with user registration. By manipulating the 'last_name' parameter, an attacker could execute arbitrary JavaScript in a victim's browser. This exploit can be executed remotely, emphasizing the need for immediate remediation to protect user data and maintain the integrity of the application. Publicly disclosed, this vulnerability poses a significant risk to users of the affected system.
Affected Version(s)
Simple Inventory System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
