CVE-2026-8136: SourceCodester Pharmacy Sales and Inventory System index.php users cross site scripting
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /index.php?page=users. Executing a manipulation of the argument Name can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8136?
CVE-2026-8136 is classified with a moderate severity level due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2026-8136?
To fix CVE-2026-8136, sanitize and validate all user inputs to the '/index.php?page=users' endpoint to prevent script injection.
What systems are affected by CVE-2026-8136?
CVE-2026-8136 affects SourceCodester Pharmacy Sales and Inventory System version 1.0.
What type of vulnerability is CVE-2026-8136?
CVE-2026-8136 is a cross-site scripting (XSS) vulnerability that can be exploited through manipulated user inputs.
Can CVE-2026-8136 impact user accounts?
Yes, CVE-2026-8136 can potentially impact user accounts by allowing an attacker to execute malicious scripts in the context of a user's session.