A cross-site scripting vulnerability exists in Rizwan17's inventory-management-system up to a specific commit (bfe78a330d01bb26b9daec5dc9ecd5c77900e03f). The issue is located in the login page's handling of the 'msg' argument in index.php. This could allow an attacker to inject malicious scripts. The system does not use versioning, making it difficult to determine affected and unaffected releases. The pro [truncated]
A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. The function update_record of the file includes/manage.php is affected by sql injection via the arguments update_category, cid, update_brand, or update_product. This issue can be exploited remotely and a public exploit is available.