Cross Site Scripting Flaw in Rizwan17 Inventory Management System Login Page
CVE-2026-87926
Key Information:
- Vendor
Rizwan17
- Vendor
- CVE Published:
- 9 September 2026
Badges
What is CVE-2026-87926?
A vulnerability has been identified in the Rizwan17 inventory management system that permits cross site scripting (XSS) attacks through the manipulation of the 'msg' argument in the index.php file associated with the Login Page component. This flaw allows attackers to execute code remotely, potentially compromising user trust and data integrity. Despite being reported early to the project maintainers, no action has been taken to address the issue. Users of the affected range should be aware of the exploit's existence, as it has been publicly disclosed.
Affected Version(s)
inventory-management-system bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
