CVE-2026-90696: SourceCodester Inventory Management System Product Management products_handler.php cross site scripting
A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/productshandler.php of the component Product Management Module. Executing a manipulation of the argument ProductName can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs low-privileged access and must be able to induce user interaction. The attack can be conducted remotely.
Which input and component are affected?
The issue affects unknown functionality in /api/products_handler.php within the Product Management Module. It is triggered through manipulation of the Product_Name argument.
Is exploitation publicly available?
Yes. The exploit has been publicly disclosed and may be used by attackers.