Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS in SourceCodester Sales and Inventory System via Unsanitized Website Field |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System |
|
| CPEs | cpe:2.3:a:ahsanriaz26gmailcom:sales_and_inventory_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Ahsanriaz26gmailcom
Ahsanriaz26gmailcom sales And Inventory System |
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS in SourceCodester Sales and Inventory System via Unsanitized Website Field |
Mon, 30 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 30 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the update_details.php file. The application fails to sanitize the "website" parameter provided in a POST request. This allows authenticated attackers to inject arbitrary web script or HTML that is stored in the database and executed whenever the store details page is accessed. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-30T15:28:43.996Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30563
Updated: 2026-03-30T15:28:38.452Z
Status : Analyzed
Published: 2026-03-30T15:16:26.460
Modified: 2026-04-01T17:46:28.023
Link: CVE-2026-30563
No data.
OpenCVE Enrichment
Updated: 2026-04-02T07:54:34Z