Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument order_date/invoice_no leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | Rizwan17 inventory-management-system Invoice Generation invoice_bill.php missing authentication | |
| First Time appeared |
Rizwan17
Rizwan17 inventory-management-system |
|
| Weaknesses | CWE-287 CWE-306 |
|
| CPEs | cpe:2.3:a:rizwan17:inventory-management-system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rizwan17
Rizwan17 inventory-management-system |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-09T22:45:13.045Z
Reserved: 2026-09-09T16:11:15.175Z
Link: CVE-2026-87924
No data.
Status : Received
Published: 2026-09-09T23:16:56.430
Modified: 2026-09-09T23:16:56.430
Link: CVE-2026-87924
No data.
OpenCVE Enrichment
Updated: 2026-09-10T00:45:07Z