CVE-2026-30563: XSS
Published Mar 30, 2026
·Updated
A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the updatedetails.php file. The application fails to sanitize the "website" parameter provided in a POST request. This allows authenticated attackers to inject arbitrary web script or HTML that is stored in the database and executed whenever the store details page is accessed.
Affected Software
2 affected components
Sourcecodester SourceCodester Sales and Inventory System=1.0
Ahsanriaz26gmailcom Sales And Inventory System=1.0
Event History
Mar 30, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software