Description
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /index.php?page=categories. Performing a manipulation of the argument ID results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-04-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Cross‑Site Scripting in SourceCodester Pharmacy Sales and Inventory System
Action: Patch
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw located in the file /index.php?page=categories. By manipulating the ID query parameter, an attacker can inject arbitrary client‑side scripts that are executed in the browsers of visitors to the affected page. The flaw is a typical reflected or stored XSS governed by CWE‑79 and may also involve code injection via query parameter, mapping to CWE‑94. The impact is limited to the victim’s browser, enabling session hijacking, phishing, or data theft, but does not compromise server‑side confidentiality or integrity.

Affected Systems

SourceCodester Pharmacy Sales and Inventory System 1.0.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate severity moderate impact with limited privileges. The exploit requires no authentication and can be performed by any remote attacker who can access the public URL. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been observed. Nevertheless, the availability of a public exploit means that a remote attacker can readily deploy the payload and observe the consequences. Overall, the risk is moderate but should not be ignored.

Generated by OpenCVE AI on April 28, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the SourceCodester Pharmacy Sales and Inventory System to the latest version that fixes the XSS flaw in index.php.
  • Validate and properly encode the ID parameter on the server side or apply strict input filtering to neutralize injected scripts.
  • Configure the web server or application firewall to block common XSS payloads and enforce safe coding practices for future development.

Generated by OpenCVE AI on April 28, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester pharmacy Sales And Inventory System
Vendors & Products Sourcecodester
Sourcecodester pharmacy Sales And Inventory System

Mon, 27 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /index.php?page=categories. Performing a manipulation of the argument ID results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Pharmacy Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-27T14:42:38.501Z

Reserved: 2026-04-26T19:16:16.657Z

Link: CVE-2026-7129

cve-icon Vulnrichment

Updated: 2026-04-27T14:42:20.341Z

cve-icon NVD

Status : Deferred

Published: 2026-04-27T14:16:56.867

Modified: 2026-04-27T18:36:42.937

Link: CVE-2026-7129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T04:30:21Z

Weaknesses