PatchSiren cyber security CVE debrief
CVE-2026-7200 SourceCodester CVE debrief
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0, specifically in the file /index.php?page=types. The vulnerability allows for cross-site scripting (XSS) attacks through manipulation of the ID argument. This issue can be exploited remotely, potentially leading to unauthorized actions or data exposure. Users of the affected system should apply patches or mitigations to prevent such attacks.
- Vendor
- SourceCodester
- Product
- Pharmacy Sales and Inventory System
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-28
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-28
- Advisory updated
- 2026-07-24
Who should care
Users of SourceCodester Pharmacy Sales and Inventory System 1.0, system administrators, security teams, and operators of affected deployments should apply patches or mitigations to prevent cross-site scripting attacks. Additionally, security teams should review compensating controls and monitor systems for suspicious activity.
Technical summary
The vulnerability exists in the /index.php?page=types file of SourceCodester Pharmacy Sales and Inventory System 1.0. An attacker can exploit this issue by manipulating the ID argument, leading to cross-site scripting. The attack can be launched remotely, and successful exploitation could result in unauthorized actions or data tampering. The vulnerability is categorized as cross-site scripting (XSS) and has a CVSS score of 2.1, indicating a low severity.
Defensive priority
Apply patches or mitigations to prevent cross-site scripting attacks. Implement input validation and sanitization for user-supplied data. Use a web application firewall to detect and prevent cross-site scripting attacks.
Recommended defensive actions
- Apply patches or updates provided by the vendor.
- Implement input validation and sanitization for user-supplied data.
- Use a web application firewall to detect and prevent cross-site scripting attacks.
- Monitor the system for suspicious activity.
- Review system logs for potential security incidents.
- Conduct regular security audits and vulnerability assessments.
- Implement asset inventory management to track affected systems.
Evidence notes
The CVE record was published on 2026-04-28T00:16:27.170Z and was last modified on 2026-07-24T08:10:00.150Z. The NVD entry is currently Deferred. Evidence is limited to public sources and may not reflect the full scope or impact of this vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-28T00:16:27.170Z and has not been modified since then. The NVD entry is currently Deferred.