Pharmacy POS Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Pharmacy POS PHP Script. This issue allows attackers to execute JavaScript in the context of the victim's browser. Exploitation involves sending a malicious URL that includes the u_medicine_name parameter to the victim, targeting the /edit_medicine.php page. This vulnerability could be used to steal sensitive information, such as session cookies, or to perform actions on behalf of the user.

Impact

Successful exploitation allows for the execution of arbitrary JavaScript in the victim's browser, potentially leading to the theft of sensitive information like session cookies or unauthorized actions performed on behalf of the user.

Remediation

The vulnerability has been fixed in the latest release of Pharmacy POS PHP Script.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
4.2
exploitability
5.0
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.