Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Title | SourceCodester Inventory Management System invoice.php authorization | |
| First Time appeared |
Sourcecodester
Sourcecodester inventory Management System |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:sourcecodester:inventory_management_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sourcecodester
Sourcecodester inventory Management System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T08:15:08.100Z
Reserved: 2026-09-13T05:14:37.152Z
Link: CVE-2026-90697
No data.
No data.
No data.
OpenCVE Enrichment
No data.
