Executive brief
SourceCodester Pharmacy Sales and Inventory System 1.0 is vulnerable to a security flaw that allows attackers to inject malicious scripts into the application. This occurs when creating a new supplier, where the system fails to properly clean the company name input. If an attacker successfully exploits this, they could potentially steal session information or perform unauthorized actions on behalf of other users who view the affected page.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the SourceCodester Pharmacy Sales and Inventory System 1.0. The flaw is located in the create_supplier function within the /ShowForm/create_supplier/main file. The root cause is the improper neutralization of user-supplied input in the 'company_name' parameter, which is subsequently rendered in the web interface without adequate encoding or filtering. A remote attacker with low privileges can exploit this by submitting a malicious script as a company name. When an administrative user views the supplier list or details, the script executes in their browser context, potentially allowing for session hijacking or unauthorized administrative actions. A public proof-of-concept (PoC) using a simple alert script has been disclosed.
Affected products
- SourceCodester Pharmacy Sales and Inventory System 1.0
Timeline
- 2026-05-09: disclosed: Vulnerability details and PoC shared on GitHub by researcher timeflies123.
- 2026-06-01: advisory: CVE-2026-10245 published.