ZeroHour

CVE-2026-30556

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p17
Published
()
Modified
Description

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the index.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.

Vendors
ahsanriaz26gmailcom
Products
sales and inventory system
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.