CVE-2026-30576

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters during stock entry, allowing negative financial values to be submitted. This leads to corruption of financial records, allowing attackers to manipulate inventory asset values and procurement costs.
Configurations

Configuration 1 (hide)

cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:*

History

31 Mar 2026, 16:14

Type Values Removed Values Added
CPE cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:*
First Time Senior-walter
Senior-walter web-based Pharmacy Product Management System
References () https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-Management-System/Logic-AddStock-NegativePrice.md - () https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-Management-System/Logic-AddStock-NegativePrice.md - Exploit, Third Party Advisory

27 Mar 2026, 20:16

Type Values Removed Values Added
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

27 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 17:16

Updated : 2026-03-31 16:14


NVD link : CVE-2026-30576

Mitre link : CVE-2026-30576

CVE.ORG link : CVE-2026-30576


JSON object : View

Products Affected

senior-walter

  • web-based_pharmacy_product_management_system
CWE
CWE-20

Improper Input Validation