Junglewise Threat Intelligence

CVE-2026-10246: SourceCodester Pharmacy Sales and Inventory System XSS in create_medicine_presentation

CVE-2026-10246 · Severity: low · CVSS 3.5 · Published 2026-06-01

Technologies: SourceCodester Pharmacy Sales and Inventory System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Pharmacy Sales and Inventory System, a web application used for managing pharmaceutical stock and sales. An attacker can inject malicious scripts into the system's medicine presentation forms. If a legitimate user views the affected page, the attacker could potentially steal login session information or perform unauthorized actions on the user's behalf.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0. The flaw is located in the 'create_medicine_presentation' function within the '/ShowForm/create_medicine_presentation/main' file. The application fails to properly validate or encode the 'medicine_presentation' parameter before rendering it in the web interface. A remote attacker with low privileges can exploit this by submitting a malicious script payload, which will execute in the context of any user who views the affected record. This can lead to session hijacking or unauthorized browser-based actions. No official patch has been identified at this time.

Affected products

  • SourceCodester Pharmacy Sales and Inventory System 1.0

Timeline

  • 2026-05-09: disclosed: Vulnerability details and POC shared on GitHub.
  • 2026-06-01: advisory: CVE-2026-10246 published.

References

Related threats