CVE-2026-30576

HIGH

SourceCodester Pharmacy Product Management System 1.0 - Business Logic

Title source: llm
STIX 2.1

Description

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters during stock entry, allowing negative financial values to be submitted. This leads to corruption of financial records, allowing attackers to manipulate inventory asset values and procurement costs.

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 16.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
senior-walter/web-based_pharmacy_product_management_system 1.0
Published Mar 27, 2026
Tracked Since Mar 29, 2026