Junglewise Threat Intelligence

CVE-2026-10247: SourceCodester Pharmacy Sales and Inventory System XSS in create_generic_name

CVE-2026-10247 · Severity: low · CVSS 3.5 · Published 2026-06-01

Technologies: SourceCodester Pharmacy Sales and Inventory System. Vendors: SourceCodester.

Executive brief

The Pharmacy Sales and Inventory System, a web application used for managing pharmaceutical stock and sales, contains a security flaw that allows for cross-site scripting (XSS). An attacker can exploit this to execute malicious scripts in the browsers of other users, potentially leading to the theft of session cookies or unauthorized actions performed on behalf of legitimate users. This could compromise the privacy of staff accounts and the integrity of the inventory data.

Technical details

A cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0 within the create_generic_name function of the /ShowForm/create_generic_name/main file. The vulnerability is caused by insufficient input validation and output encoding of the 'generic_name' parameter. A remote attacker with low privileges can inject malicious JavaScript that executes when a victim views the affected page. Successful exploitation can lead to session hijacking, cookie theft, or unauthorized browser-based actions. A public exploit (Proof of Concept) is available.

Affected products

  • SourceCodester Pharmacy Sales and Inventory System 1.0

Timeline

  • 2026-05-09: disclosed: Vulnerability reported on GitHub by researcher timeflies123.
  • 2026-06-01: advisory: CVE-2026-10247 published.

References

Related threats