CVE-2026-5810: SourceCodester Sales and Inventory System GET Parameter delete.php cross site scripting
A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argument ID causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5810?
CVE-2026-5810 has a high severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-5810?
To fix CVE-2026-5810, ensure proper input validation and sanitization for the GET parameters in the delete.php file.
What impact does CVE-2026-5810 have on the SourceCodester Sales and Inventory System?
CVE-2026-5810 allows attackers to execute arbitrary scripts in the context of the user's browser, potentially compromising sensitive data.
Who is affected by CVE-2026-5810?
CVE-2026-5810 affects users of SourceCodester Sales and Inventory System version 1.0 who utilize the delete.php component.
Is there a patch available for CVE-2026-5810?
As of now, there is no official patch for CVE-2026-5810, so it is recommended to apply manual code changes to mitigate the vulnerability.