CVE-2026-30564: XSS
Published Mar 30, 2026
·Updated
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the viewpayments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
2 affected components
Sourcecodester Sales and Inventory System=1.0
Ahsanriaz26gmailcom Sales And Inventory System=1.0
Event History
Mar 30, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software