PT-2025-37767 · Seniorwalter · Web-Based Pharmacy Product Management System

·

CVE-2025-56274

·

Published

2025-09-15

·

Updated

2025-12-23

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Web-based Pharmacy Product Management System version 1.0
Description The software contains an Incorrect Access Control issue. This allows users with limited privileges to create sessions with higher privileges, such as those of an administrator. This enables them to perform sensitive actions, including adding new users.
Recommendations Apply appropriate access controls to prevent low-privileged users from forging high-privileged sessions.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-56274

Affected Products

Web-Based Pharmacy Product Management System