CVE-2026-90694: SourceCodester Inventory Management System Customer Management customers_handler.php cross site scripting
Published Sep 14, 2026
·Updated
A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customershandler.php of the component Customer Management Module. Such manipulation of the argument CustomerName leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Sourcecodester Inventory Management System=1.0
Event History
Sep 14, 2026
CVE Published
via MITRE·07:30 AM
Data Sourced
via MITRE·07:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
How practical is exploitation?
The attack can be executed remotely with low attack complexity, but it requires low-level privileges and user interaction. A public exploit has been disclosed, which may increase the likelihood of attempts.
2
What is the expected security impact?
The reported impact is limited to integrity, with no reported confidentiality or availability impact. The scope is unchanged.