---
id: CVE-2026-87926
title: >-
  A flaw has been found in Rizwan17 inventory-management-system up to
  bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
summary: >-
  A flaw has been found in Rizwan17 inventory-management-system up to
  bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown
  processing of the file index.php of the component Login Page. Executing a
  manipulation of the a…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: Rizwan17
product: inventory-management-system
affected:
  - inventory-management-system bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
published: '2026-09-10'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T19:17:53.500'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87926'
references:
  - url: 'https://github.com/Rizwan17/inventory-management-system/'
    label: cna@vuldb.com
  - url: 'https://github.com/Rizwan17/inventory-management-system/issues/11'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-87926'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/911140'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/401813'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/401813/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.0047
epssPercentile: 0.38074
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T17:12:52.192773Z'
ingestedAt: '2026-09-10T00:26:24.578Z'
---

## Overview

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
