CVE-2026-30574

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attacker can manipulate the request to purchase a quantity that is significantly higher than the actual available stock.
Configurations

Configuration 1 (hide)

cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:*

History

31 Mar 2026, 18:03

Type Values Removed Values Added
References () https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-Management-System/Logic-AddSales-Overselling.md - () https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-Management-System/Logic-AddSales-Overselling.md - Exploit, Third Party Advisory
CPE cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:*
First Time Senior-walter
Senior-walter web-based Pharmacy Product Management System

27 Mar 2026, 20:16

Type Values Removed Values Added
CWE CWE-841
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

27 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 17:16

Updated : 2026-06-17 10:32


NVD link : CVE-2026-30574

Mitre link : CVE-2026-30574

CVE.ORG link : CVE-2026-30574


JSON object : View

Products Affected

senior-walter

  • web-based_pharmacy_product_management_system
CWE
CWE-841

Improper Enforcement of Behavioral Workflow