CVE-2026-90697
SourceCodester Inventory Management System invoice.php authorization
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
| CWE | CWE-639 CWE-285 |
| Vendor | sourcecodester |
| Product | inventory management system |
| Published | Sep 14, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for sourcecodester inventory management system
Be the first to know when new medium vulnerabilities affecting sourcecodester inventory management system are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
SourceCodester / Inventory Management System
1.0
References
vuldb.com: https://vuldb.com/vuln/403230 vuldb.com: https://vuldb.com/vuln/403230/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90697 vuldb.com: https://vuldb.com/submit/916047 gist.github.com: https://gist.github.com/fhewm98/079112d415afa63ed1368a798a352665 sourcecodester.com: https://www.sourcecodester.com/
Credits
๐ Mohammed Faheem (VulDB User)