CVE-2026-3262

A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

cpe:2.3:a:go2ismail:asp.net-core-inventory-order-management-system:*:*:*:*:*:*:*:*

History

03 Mar 2026, 00:39

Type Values Removed Values Added
References () https://github.com/Ghufran2/CVE-Asp.Net-Core-Inventory-Order-Management-System-Advisories/blob/main/Asp.Net-Core-Inventory-Order-Management-System%20Privilege%20Escalation%20via%20Client-Side%20Redirect%20Bypass.md - () https://github.com/Ghufran2/CVE-Asp.Net-Core-Inventory-Order-Management-System-Advisories/blob/main/Asp.Net-Core-Inventory-Order-Management-System%20Privilege%20Escalation%20via%20Client-Side%20Redirect%20Bypass.md - Exploit, Mitigation, Third Party Advisory
References () https://vuldb.com/?ctiid.347985 - () https://vuldb.com/?ctiid.347985 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347985 - () https://vuldb.com/?id.347985 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.758333 - () https://vuldb.com/?submit.758333 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:go2ismail:asp.net-core-inventory-order-management-system:*:*:*:*:*:*:*:*
First Time Go2ismail asp.net-core-inventory-order-management-system
Go2ismail

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en go2ismail Asp.Net-Core-Inventory-Order-Management-System hasta 9.20250118. Afectada es una función desconocida del componente Interfaz Administrativa. Dicha manipulación lleva a ejecución después de redirección. El ataque puede ser lanzado remotamente. El exploit ha sido divulgado al público y puede ser usado. El proveedor fue contactado tempranamente sobre esta divulgación pero no respondió de ninguna manera.

26 Feb 2026, 22:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 22:20

Updated : 2026-03-03 00:39


NVD link : CVE-2026-3262

Mitre link : CVE-2026-3262

CVE.ORG link : CVE-2026-3262


JSON object : View

Products Affected

go2ismail

  • asp.net-core-inventory-order-management-system
CWE
CWE-698

Execution After Redirect (EAR)

CWE-705

Incorrect Control Flow Scoping