Vulnerability Description
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attacker can manipulate the request to purchase a quantity that is significantly higher than the actual available stock.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Senior-Walter | Web-Based Pharmacy Product Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-ManagemExploitThird Party Advisory
FAQ
What is CVE-2026-30574?
CVE-2026-30574 is a vulnerability with a CVSS score of 7.5 (HIGH). A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) excee...
How severe is CVE-2026-30574?
CVE-2026-30574 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-30574?
Check the references section above for vendor advisories and patch information. Affected products include: Senior-Walter Web-Based Pharmacy Product Management System.