Show filters
55 Total Results
Displaying 21-30 of 55
Sort by:
Attacker Value
Unknown

CVE-2023-46580

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.
Attacker Value
Unknown

CVE-2023-46450

Disclosure Date: October 26, 2023 (last updated October 31, 2023)
Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.
Attacker Value
Unknown

CVE-2023-46449

Disclosure Date: October 26, 2023 (last updated October 31, 2023)
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.
Attacker Value
Unknown

CVE-2023-39712

Disclosure Date: September 08, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.
Attacker Value
Unknown

CVE-2023-39711

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.
Attacker Value
Unknown

CVE-2023-4749

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to file inclusion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-238638 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-39714

Disclosure Date: September 01, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.
Attacker Value
Unknown

CVE-2023-39710

Disclosure Date: September 01, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.
Attacker Value
Unknown

CVE-2023-39709

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.
Attacker Value
Unknown

CVE-2023-39708

Disclosure Date: August 28, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy section.