Executive brief
A security vulnerability exists in the SourceCodester Pharmacy Sales and Inventory System, a web application used for managing pharmaceutical stock and sales. An attacker can exploit this flaw to execute malicious scripts in the browsers of other users who visit a specific page. This could lead to the theft of login session information, unauthorized actions performed on behalf of users, or the defacement of the application's interface.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0. The issue is located in the '/index.php?page=types' file, where the 'id' parameter is processed without sufficient input validation or output encoding. A remote, unauthenticated attacker can craft a malicious URL containing a script payload; when a victim clicks this link, the script executes within the context of their browser session. This can be used to capture session cookies or perform unauthorized API requests. A public exploit (Proof of Concept) has been disclosed.
Affected products
- SourceCodester Pharmacy Sales and Inventory System 1.0
Timeline
- 2026-04-09: disclosed: Vulnerability reported on GitHub with PoC
- 2026-04-28: advisory: NVD/VulDB advisory published