Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-30573
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss.
CVE-2026-30574
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attacker can manipulate the request to purchase a quantity that is significantly higher than the actual available stock.
CVE-2026-30576
Business Logic Vulnerability Allowing Negative Financial Values in Web‑Based Pharmacy Product Management System
CVE-2026-30575
Negative Quantity Stock Entry Exploit in Pharmacy Management System
CVE-2026-3766
SourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site scripting
