A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss.
References
| Link | Resource |
|---|---|
| https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-Management-System/Logic-AddSales-NegativePrice.md | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Apr 2026, 12:06
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Senior-walter
Senior-walter web-based Pharmacy Product Management System |
|
| CPE | cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:* | |
| References | () https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-Management-System/Logic-AddSales-NegativePrice.md - Exploit, Third Party Advisory |
01 Apr 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | CWE-1284 |
01 Apr 2026, 15:22
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 15:22
Updated : 2026-06-17 10:32
NVD link : CVE-2026-30573
Mitre link : CVE-2026-30573
CVE.ORG link : CVE-2026-30573
JSON object : View
Products Affected
senior-walter
- web-based_pharmacy_product_management_system
CWE
CWE-1284
Improper Validation of Specified Quantity in Input
