CVE-2026-90695

A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 08:16

Updated : 2026-09-14 20:56


NVD link : CVE-2026-90695

Mitre link : CVE-2026-90695

CVE.ORG link : CVE-2026-90695


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')