CVE-2026-30573

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss.
Configurations

Configuration 1 (hide)

cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:*

History

07 Apr 2026, 12:06

Type Values Removed Values Added
First Time Senior-walter
Senior-walter web-based Pharmacy Product Management System
CPE cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:*
References () https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-Management-System/Logic-AddSales-NegativePrice.md - () https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-Management-System/Logic-AddSales-NegativePrice.md - Exploit, Third Party Advisory

01 Apr 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-1284

01 Apr 2026, 15:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 15:22

Updated : 2026-06-17 10:32


NVD link : CVE-2026-30573

Mitre link : CVE-2026-30573

CVE.ORG link : CVE-2026-30573


JSON object : View

Products Affected

senior-walter

  • web-based_pharmacy_product_management_system
CWE
CWE-1284

Improper Validation of Specified Quantity in Input