CVE-2026-10255: SourceCodester Pharmacy Sales and Inventory System ShowForm.php sell_statement access control

Published Jun 1, 2026
·
Updated

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sellstatement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Affected Software

1 affected component
Sourcecodester SourceCodester Pharmacy Sales and Inventory System=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove SourceCodester Pharmacy Sales and Inventory System 1.0 from your environment.

    If the application is not required, uninstall or remove the SourceCodester Pharmacy Sales and Inventory System instances from exposed hosts to eliminate the vulnerable component.

  2. Configuration

    Modify ShowForm.php::sell_statement to perform strict server-side authentication and authorization checks (verify session tokens, user identity and roles) and deny access unless the caller is authorized. Ensure access is not controlled solely by client-side checks.

    SourceCodester Pharmacy Sales and Inventory System (application/controllers/ShowForm.php - sell_statement) access_control / authorization checks = enforce server-side authentication and authorization for sell_statement
  3. Compensating control

    Until a code fix is deployed, block or restrict access to the sell_statement endpoint using a firewall, network ACL, or WAF rule (allow only trusted IPs or require authentication at the edge) to prevent remote exploitation.

Event History

Jun 1, 2026
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Mar 11, 58386
Event
via NVD·10:04 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10255?

CVE-2026-10255 has a medium severity level of 5.3.

2

What is the nature of CVE-2026-10255 vulnerability?

CVE-2026-10255 involves improper access controls in the sell_statement function of the ShowForm.php file.

3

How can I protect my system from CVE-2026-10255?

To protect against CVE-2026-10255, ensure proper access controls and permissions for the affected application.

4

Is CVE-2026-10255 remotely exploitable?

Yes, CVE-2026-10255 can be exploited remotely.

5

What versions of the SourceCodester Pharmacy Sales and Inventory System are affected by CVE-2026-10255?

CVE-2026-10255 affects SourceCodester Pharmacy Sales and Inventory System version 1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203