CVE-2023-46580

MEDIUM

Inventory Management V1.0 - XSS

Title source: llm
STIX 2.1

Description

Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.

Scores

CVSS v3 5.4
EPSS 0.0018
EPSS Percentile 39.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
code-projects/inventory_management 1.0
Published Nov 14, 2023
Tracked Since Feb 18, 2026