Junglewise Threat Intelligence

CVE-2025-56274: SourceCodester Web-based Pharmacy Product Management System incorrect access control in add-admin.php

CVE-2025-56274 · Severity: high · CVSS 8.1 · Published 2025-09-15

Vendors: SourceCodester.

Executive brief

A vulnerability exists in the SourceCodester Web-based Pharmacy Product Management System, a tool used for managing pharmaceutical inventory and users. An attacker with a low-privileged account can bypass security restrictions to perform administrative tasks, such as creating new unauthorized user accounts. This could lead to a full takeover of the system and unauthorized access to sensitive pharmacy data.

Technical details

An incorrect access control vulnerability exists in the 'add-admin.php' component of SourceCodester Web-based Pharmacy Product Management System 1.0. The application fails to properly validate the authorization level of a user session when processing administrative requests. A remote attacker with low-privileged credentials can exploit this by capturing an administrative request and substituting their own session cookies, or otherwise forging a high-privileged session. Successful exploitation allows the attacker to perform sensitive operations, such as creating new administrative users, effectively escalating their privileges to full system control. A Proof of Concept (PoC) has been disclosed demonstrating the addition of a new user via session manipulation.

Affected products

  • SourceCodester Web-based Pharmacy Product Management System 1.0

Timeline

  • 2025-09-15: advisory: Initial NVD publication date
  • 2025-09-16: other: CISA-ADP enrichment and SSVC assessment added

References