CVE-2009-4596 describes a cross-site scripting (XSS) vulnerability in PHP Inventory version 1.2, specifically within the index.php file. This flaw allows remote attackers to inject malicious web scripts or HTML by manipulating the sup_id parameter during a suppliers details action. With a CVSS score of 4.3, it is a medium-severity vulnerability that can be exploited over the network with medium attack complexity, potentially leading to information compromise (C:N/I:P/A:N). There is no evidence of active exploitation, and while an authentication bypass exploit exists on ExploitDB, it is not directly related to this XSS vulnerability. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2CPE matchmatch criteria | cpe:2.3:a:phpwares:php_inventory:1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.