Amirsanni · Mini-Inventory-And-Sales-Management-System · CVE-2026-100904
**Name of the Vulnerable Software and Affected Versions**
amirsanni mini-inventory-and-sales-management-system versions up to 81bf0b55f5933f3b0dbb1583204a612e06605b95
**Description**
A cross site scripting issue exists within the Items Management Module in the file application/controllers/Items.php. Remote exploitation is possible by manipulating the `itemName` argument, which allows the execution of malicious scripts in the victim's browser.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.