Executive brief
The LalanaChami Pharmacy Management System, used for managing drug inventory and medical prescriptions, contains a critical security flaw where multiple administrative functions are accessible without a password. An attacker can remotely download the entire database of users (including password hashes), view private medical prescriptions, and modify or delete inventory and financial records. This could lead to a total loss of patient privacy, disruption of pharmacy operations, and unauthorized changes to medication data.
Technical details
The application suffers from missing authentication (CWE-306) across several backend routes including /api/user, /api/inventory, /api/doctorOder, and /api/sales. The root cause is the absence of authentication middleware in the Express.js router configurations. An unauthenticated remote attacker can perform GET requests to dump the entire user collection (including bcrypt password hashes), POST/PUT/DELETE requests to manipulate drug inventory, and access doctor prescriptions and financial records. While the CVE description specifically mentions privilege escalation via the signup endpoint, the underlying technical issue is a systemic lack of access control across the entire API surface.
Affected products
- LalanaChami Pharmacy Management System commit 5c3d028
Timeline
- 2026-05-19: disclosed: Vulnerability details and PoC published via GitHub Gist
- 2026-05-19: advisory: CVE-2026-31070 published in NVD