SourceCodester Web-Based Pharmacy Product Management System Incorrect Access Control Vulnerability

Vulnerability

A vulnerability allowing incorrect access control has been identified in SourceCodester Web-Based Pharmacy Product Management System version 1.0. This issue enables low-privileged users to impersonate high-privileged users, such as administrators, and execute sensitive actions, including the addition of new users.

Impact

Exploitation of this vulnerability could lead to unauthorized user creation, potentially allowing for elevated privileges or access to restricted functionalities.

Reproduction

To reproduce this vulnerability, log into the application as an admin user and add a new user. Then, open an incognito browser and log in as a low-privileged user, such as the one just created. This user will only have access to personal information and will not be able to add new users. Next, capture the admin user's data package, including the session cookie, and replace the low-privileged user's cookie with the admin data package. This will grant the low-privileged user admin privileges, allowing them to add new users.

Added: Sep 15, 2025, 11:01 PM
Updated: Sep 15, 2025, 11:01 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
0.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.