Rizwan17 · Inventory Management System · CVE-2026-90565
**Name of the Vulnerable Software and Affected Versions**
Rizwan17 inventory-management-system versions up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
**Description**
An improper access control issue exists in the `dashboard.php` file. A remote attacker can exploit this by manipulating the `userid` argument, allowing unauthorized access to the system.
**Recommendations**
As a temporary workaround, restrict access to the `dashboard.php` file or avoid using the `userid` argument until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.