216.73.216.133

CVE-2026-30573

· Published 01/04/2026 15:22 · Modified 01/04/2026 18:16

Labels: CVE-2026-30573 2026-04-01CVE-2026-30573CWE-1284[email protected]

Essential information

Published
01/04/2026 15:22
Modified
01/04/2026 18:16
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS metrics

Description

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sourcecodester / pharmacy product management system cpe:2.3:a:sourcecodester:pharmacy_product_management_system:1.0:*:*:*:*:*:*:*

References