Executive brief
A vulnerability exists in the SourceCodester Web-based Pharmacy Product Management System, a tool used for managing pharmaceutical inventory and users. An attacker with a low-privileged account can bypass security restrictions to perform administrative tasks, such as creating new unauthorized user accounts. This could lead to a full takeover of the system and unauthorized access to sensitive pharmacy data.
Technical details
An incorrect access control vulnerability exists in the 'add-admin.php' component of SourceCodester Web-based Pharmacy Product Management System 1.0. The application fails to properly validate the authorization level of a user session when processing administrative requests. A remote attacker with low-privileged credentials can exploit this by capturing an administrative request and substituting their own session cookies, or otherwise forging a high-privileged session. Successful exploitation allows the attacker to perform sensitive operations, such as creating new administrative users, effectively escalating their privileges to full system control. A Proof of Concept (PoC) has been disclosed demonstrating the addition of a new user via session manipulation.
Affected products
- SourceCodester Web-based Pharmacy Product Management System 1.0
Timeline
- 2025-09-15: advisory: Initial NVD publication date
- 2025-09-16: other: CISA-ADP enrichment and SSVC assessment added