Impact
The vulnerability resides in the add‑sales.php component of SourceCodester Pharmacy Product Management System 1.0. An attacker can manipulate the posted txtqty parameter, submitting values such as negative numbers. The component then processes these inputs without proper validation, leading to unintended sales records that distort inventory counts and financial calculations. This flaw undermines the integrity of transaction data and can result in incorrect accounting or stock shortages.
Affected Systems
The flaw affects the Pharmacy Product Management System version 1.0 supplied by SourceCodester. Systems running this edition are typically found in small pharmacy or retail environments and may not have hardened input handling. No other version numbers are indicated in the vulnerability report.
Risk and Exploitability
The vulnerability has a moderate severity rating with a base score of 5.3. No exploitation probability data is available, and the issue has not been identified as a known exploited vulnerability. Attackers can carry out the exploit remotely by sending crafted HTTP POST requests to the vulnerable add‑sales.php endpoint; this inference is drawn from the description that the attack can be initiated from a remote location.
OpenCVE Enrichment