


Perceptive Security
SOC/SIEM Consultancy

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the…
Published:
26 March 2026 at 23:00:00
Alert date:
27 March 2026 at 21:04:38
Source:
nvd.nist.gov
Web Technologies
A business logic vulnerability in SourceCodester Pharmacy Product Management System 1.0 allows attackers to manipulate sales requests to purchase quantities exceeding available stock. The vulnerability exists in the add-sales.php file where the application fails to verify if the requested sales quantity (txtqty) exceeds available inventory levels. This oversight enables attackers to exploit the system by submitting purchase requests for significantly higher quantities than what is actually in stock, potentially leading to inventory discrepancies and business logic bypass.
Technical details
Mitigation steps:
Affected products:
SourceCodester Pharmacy Product Management System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30574
https://github.com/meifukun/Web-Security-PoCs/blob/main/Pharmacy-Product-Management-System/Logic-AddSales-Overselling.md
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
