CVE-2026-3766: SourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site scripting
A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the argument fullname results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3766?
CVE-2026-3766 is categorized as a high-severity cross-site scripting vulnerability.
How do I fix CVE-2026-3766?
To fix CVE-2026-3766, sanitize and validate user inputs in the edit-profile.php file to prevent XSS attacks.
What software is affected by CVE-2026-3766?
CVE-2026-3766 affects the SourceCodester Web-based Pharmacy Product Management System version 1.0.
What impact does CVE-2026-3766 have on users?
CVE-2026-3766 could allow attackers to execute arbitrary scripts in the context of the user's browser, compromising user data.
Is there a workaround for CVE-2026-3766?
A temporary workaround for CVE-2026-3766 is to restrict access to the vulnerable edit-profile.php function until a patch is applied.