CVE-2025-56274

8.1

SourceCodester · Web-based Pharmacy Product Management System

SourceCodester Web-based Pharmacy Product Management System 1.0 contains an incorrect access control flaw allowing low-privileged users to escalate privileges to administrator.

Executive summary

A critical access control vulnerability in SourceCodester Pharmacy Product Management System 1.0 allows low-privileged users to hijack administrative sessions and perform unauthorized actions.

Vulnerability

The application suffers from incorrect access control, which enables an authenticated low-privileged user to forge administrative sessions. This allows unauthorized users to perform sensitive administrative operations, including the creation of new user accounts.

Business impact

The ability for a low-privileged user to gain administrative control over a pharmacy management system poses a severe risk to data integrity and system security. With a CVSS score of 8.1, this high-severity flaw could lead to unauthorized access to sensitive patient or inventory data, potential system-wide sabotage, or the creation of persistent backdoors by malicious actors.

Remediation

Immediate Action: Since no official patch is currently available, administrators should restrict network access to the application to trusted internal segments only.

Proactive Monitoring: Review system access logs for anomalous account creation events or unauthorized activity originating from low-privileged user accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect session tokens and identify irregular privilege escalation patterns.

Exploitation status

Public Exploit Available: Yes: a public proof-of-concept exists, attributed to the researcher write-up referenced in the CVE record.

Analyst recommendation

Given the lack of an official vendor patch, this vulnerability presents a significant risk to organizational integrity. Administrators must prioritize limiting exposure of the application to the internet and closely monitor for unauthorized administrative actions until a formal fix is released by the vendor.

More SourceCodester CVEs

Sources