PT-2026-45394 · Sourcecodester · Pharmacy Sales/Inventory System
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Pharmacy Sales and Inventory System versions prior to 1.1
Description
An issue in the Supplier Creation Interface allows remote exploitation via CSV injection. This occurs within the
create supplier() function located in the /Export csv/export file when the Address/Company Name argument is manipulated. CSV injection is a technique where untrusted input is embedded into a CSV file, which can execute malicious commands when opened in a spreadsheet application.Recommendations
Update the system to a version later than 1.0.
As a temporary workaround, restrict access to the
create supplier() function in the /Export csv/export file to minimize the risk of exploitation.Exploit
Fix
RCE
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pharmacy Sales/Inventory System