PT-2026-90871 · Rizwan17 · Inventory Management System

·

CVE-2026-90566

·

Published

2026-09-13

·

Updated

2026-09-14

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Rizwan17 inventory-management-system versions up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f
Description A weakness in the Registration Handler component allows remote attackers to achieve improper authorization. This occurs through the manipulation of the usertype argument within the createUserAccount() function located in the register.php file.
Recommendations As a temporary workaround, restrict access to the createUserAccount() function in the register.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90566

Affected Products

Inventory Management System