A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sourcecodester
Sourcecodester web-based Pharmacy Product Management System |
|
| Vendors & Products |
Sourcecodester
Sourcecodester web-based Pharmacy Product Management System |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Negative Pricing in Pharmacy Sales Leads to Financial Loss |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss. | |
| Weaknesses | CWE-1284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-01T00:00:00.000Z
Updated: 2026-04-01T17:52:39.630Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30573
Updated: 2026-04-01T17:49:29.409Z
Status : Awaiting Analysis
Published: 2026-04-01T15:22:59.387
Modified: 2026-04-03T16:11:11.357
Link: CVE-2026-30573
No data.