Executive brief
A security vulnerability exists in the SourceCodester Pharmacy Sales and Inventory System, a web application used for managing pharmaceutical stock and sales. An attacker can inject malicious scripts into the system via the medicine name field. If a user views the affected page, the attacker could steal login session information or perform unauthorized actions on the user's behalf.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0. The flaw is located in the 'medicine_name' parameter within the '/ShowForm/create_medicine_name/main' component. The application fails to properly validate or encode user-supplied input before rendering it back to the web page. A remote attacker can exploit this by tricking a user into clicking a specially crafted link or submitting a malicious payload, leading to the execution of arbitrary JavaScript in the victim's browser context. This can result in session hijacking or unauthorized data access. No authentication is required to initiate the attack.
Affected products
- SourceCodester Pharmacy Sales and Inventory System 1.0
Timeline
- 2026-05-09: disclosed: Initial disclosure on GitHub issues
- 2026-06-01: advisory: NVD publication date