Junglewise Threat Intelligence

CVE-2026-5812: SourceCodester Pharmacy Product Management System business logic error in add-sales.php

CVE-2026-5812 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Vendors: SourceCodester.

Executive brief

A business logic vulnerability exists in the SourceCodester Pharmacy Product Management System, a software used to track pharmaceutical inventory and sales. An attacker can manipulate sales records to artificially increase stock levels by submitting negative quantity values. This can lead to inaccurate inventory data, corrupted financial reports, and potential disruption of pharmacy operations.

Technical details

A business logic vulnerability in SourceCodester Pharmacy Product Management System 1.0 resides in the 'add-sales.php' file due to improper input validation of the 'txtqty' POST parameter. The application fails to verify that the quantity of items sold is a positive integer. When a negative value is submitted, the backend logic (NewStock = CurrentStock - SoldQty) performs a double negative operation, effectively adding to the stock instead of subtracting from it. A remote attacker with low privileges (e.g., a pharmacist account) can exploit this to artificially inflate inventory levels and corrupt sales records. A public exploit (PoC) has been released, but no official patch is currently documented.

Affected products

  • SourceCodester Pharmacy Product Management System 1.0

Timeline

  • 2026-04-08: disclosed: Initial disclosure and NVD publication
  • 2026-04-08: advisory
  • 2026-04-09: other: CISA-ADP SSVC assessment added

References