Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SourceCodester Pharmacy Product Management System 安全漏洞
Vulnerability Description
SourceCodester Pharmacy Product Management System是SourceCodester开源的一个药品管理系统。 SourceCodester Pharmacy Product Management System 1.0版本存在安全漏洞,该漏洞源于add-sales.php文件未能验证txtprice和txttotalcost参数,可能导致攻击者为销售交易提交负值,从而引发错误的财务计算、损坏销售报告和潜在的财务损失。
CVSS Information
N/A
Vulnerability Type
N/A