CVE-2026-11520 PUBLISHED

SourceCodester Inventory System header.php cross site scripting

Assigner: VulDB
Reserved: 07.06.2026 Published: 08.06.2026 Updated: 08.06.2026

A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Multiple parameters might be affected.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.1

Product Status

Vendor SourceCodester
Product Inventory System
Versions
  • Version 1.0 is affected

Credits

  • Kamran Saifullah (VulDB User) reporter
  • VulDB Vulnerability Moderation Team coordinator

References

Problem Types

  • Cross Site Scripting CWE
  • Code Injection CWE