CVE-2026-9414: SourceCodester Indian Invoicing System Invoice Template Render Database-Backed add_order.php cross site scripting
A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an unknown function of the file /Invoicing/add_order.php of the component Invoice Template Render Database-Backed. The manipulation of the argument customer_name results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9414?
The severity of CVE-2026-9414 is rated low, with a score of 3.5.
What type of vulnerability is CVE-2026-9414?
CVE-2026-9414 is a cross site scripting (XSS) vulnerability found in the add_order.php file.
How can I mitigate CVE-2026-9414 in the SourceCodester Indian Invoicing System?
To mitigate CVE-2026-9414, ensure proper validation and sanitization of the customer_name input to prevent XSS attacks.
What systems are affected by CVE-2026-9414?
CVE-2026-9414 affects the SourceCodester Indian Invoicing System versions up to 0.x/1.0.
What is the impact of exploitation of CVE-2026-9414?
Exploitation of CVE-2026-9414 can lead to unauthorized execution of scripts in a user's browser, affecting the integrity of the application.