Junglewise Threat Intelligence

CVE-2026-7200: SourceCodester Pharmacy Sales and Inventory System XSS in types page

CVE-2026-7200 · Severity: medium · CVSS 4.3 · Published 2026-04-28

Technologies: SourceCodester Pharmacy Sales and Inventory System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Pharmacy Sales and Inventory System, a web application used for managing pharmaceutical stock and sales. An attacker can exploit this flaw to execute malicious scripts in the browsers of other users who visit a specific page. This could lead to the theft of login session information, unauthorized actions performed on behalf of users, or the defacement of the application's interface.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0. The issue is located in the '/index.php?page=types' file, where the 'id' parameter is processed without sufficient input validation or output encoding. A remote, unauthenticated attacker can craft a malicious URL containing a script payload; when a victim clicks this link, the script executes within the context of their browser session. This can be used to capture session cookies or perform unauthorized API requests. A public exploit (Proof of Concept) has been disclosed.

Affected products

  • SourceCodester Pharmacy Sales and Inventory System 1.0

Timeline

  • 2026-04-09: disclosed: Vulnerability reported on GitHub with PoC
  • 2026-04-28: advisory: NVD/VulDB advisory published

References

Related threats