Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

SourceCodester Pharmacy Management System edit-profile.php XSS Attack Risk

CVE-2026-3766
Summary

The SourceCodester Pharmacy Management System may allow an attacker to inject malicious code into the system, potentially allowing them to access sensitive information or take control of the system. This flaw is present in a specific function in the edit-profile.php file and can be exploited remotely. It's recommended to update to a patched version of the system or implement security patches to prevent potential attacks.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
senior-walter web-based_pharmacy_product_management_system 1.0 –
Original title
A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of t...
Original description
A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the argument fullname results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
nvd CVSS2.0 4.0
nvd CVSS3.1 3.5
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
CWE-94 Code Injection
Published: 8 Mar 2026 · Updated: 13 Mar 2026 · First seen: 8 Mar 2026