Description
Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side script execution.
Exploits (1)
exploitdb
WORKING POC
by Cemal Cihad ÇİFTÇİ · textwebappsphp
https://www.exploit-db.com/exploits/47725
References (4)
Scores
CVSS v3
6.4
EPSS
0.0006
EPSS Percentile
19.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
Bigprof/Online Inventory Manager
3.2
Published
Feb 03, 2026
Tracked Since
Feb 18, 2026