PT-2025-37767 · Seniorwalter · Web-Based Pharmacy Product Management System

Chen1-Boop

·

Published

2025-09-15

·

Updated

2025-12-23

·

CVE-2025-56274

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Web-based Pharmacy Product Management System version 1.0
Description The software contains an Incorrect Access Control issue. This allows users with limited privileges to create sessions with higher privileges, such as those of an administrator. This enables them to perform sensitive actions, including adding new users.
Recommendations Apply appropriate access controls to prevent low-privileged users from forging high-privileged sessions.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-56274

Affected Products

Web-Based Pharmacy Product Management System