CVE-2026-13570: SourceCodester Inventory Management System User Registration Endpoint users_handler.php cross site scripting
A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/usershandler.php of the component User Registration Endpoint. Performing a manipulation of the argument fullname results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13570?
CVE-2026-13570 has a severity rating of low, with a score of 3.5.
How do I fix CVE-2026-13570?
To mitigate CVE-2026-13570, sanitize and validate input data specifically for the full_name parameter in the user registration endpoint.
What type of vulnerability is CVE-2026-13570?
CVE-2026-13570 is a cross-site scripting (XSS) vulnerability affecting the SourceCodester Inventory Management System.
Which component is affected by CVE-2026-13570?
CVE-2026-13570 affects the User Registration Endpoint in the SourceCodester Inventory Management System.
What is the impact of CVE-2026-13570?
The impact of CVE-2026-13570 allows attackers to execute malicious scripts in the context of the user’s browser.