Executive brief
A security vulnerability exists in the SourceCodester Pharmacy Sales and Inventory System, a web application used for managing pharmaceutical stock and sales. An attacker can inject malicious scripts into the system's medicine presentation forms. If a legitimate user views the affected page, the attacker could potentially steal login session information or perform unauthorized actions on the user's behalf.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0. The flaw is located in the 'create_medicine_presentation' function within the '/ShowForm/create_medicine_presentation/main' file. The application fails to properly validate or encode the 'medicine_presentation' parameter before rendering it in the web interface. A remote attacker with low privileges can exploit this by submitting a malicious script payload, which will execute in the context of any user who views the affected record. This can lead to session hijacking or unauthorized browser-based actions. No official patch has been identified at this time.
Affected products
- SourceCodester Pharmacy Sales and Inventory System 1.0
Timeline
- 2026-05-09: disclosed: Vulnerability details and POC shared on GitHub.
- 2026-06-01: advisory: CVE-2026-10246 published.