CVE-2026-82625: code-projects Simple Inventory System User Registration register.php cross site scripting
A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. Such manipulation of the argument lastname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What input is affected by this issue?
The issue is associated with the last_name argument in the User Registration component's /register.php endpoint.
Can this be exploited remotely, and does an attacker need an account?
The attack may be launched remotely. The provided CVSS vector indicates no privileges are required, but user interaction is required.
What is the likely security impact?
The CVSS vector indicates an integrity impact of low, with no stated confidentiality or availability impact. Successful exploitation is cross-site scripting.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.