CVE-2026-10255: SourceCodester Pharmacy Sales and Inventory System ShowForm.php sell_statement access control
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sellstatement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SourceCodester Pharmacy Sales and Inventory System 1.0from your environment.If the application is not required, uninstall or remove the SourceCodester Pharmacy Sales and Inventory System instances from exposed hosts to eliminate the vulnerable component.
- Configuration
Modify ShowForm.php::sell_statement to perform strict server-side authentication and authorization checks (verify session tokens, user identity and roles) and deny access unless the caller is authorized. Ensure access is not controlled solely by client-side checks.
SourceCodester Pharmacy Sales and Inventory System (application/controllers/ShowForm.php - sell_statement) access_control / authorization checks = enforce server-side authentication and authorization for sell_statement - Compensating control
Until a code fix is deployed, block or restrict access to the sell_statement endpoint using a firewall, network ACL, or WAF rule (allow only trusted IPs or require authentication at the edge) to prevent remote exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10255?
CVE-2026-10255 has a medium severity level of 5.3.
What is the nature of CVE-2026-10255 vulnerability?
CVE-2026-10255 involves improper access controls in the sell_statement function of the ShowForm.php file.
How can I protect my system from CVE-2026-10255?
To protect against CVE-2026-10255, ensure proper access controls and permissions for the affected application.
Is CVE-2026-10255 remotely exploitable?
Yes, CVE-2026-10255 can be exploited remotely.
What versions of the SourceCodester Pharmacy Sales and Inventory System are affected by CVE-2026-10255?
CVE-2026-10255 affects SourceCodester Pharmacy Sales and Inventory System version 1.0.