CVE-2026-4013
Medium
|5.3Exploit Available
Plain English Summary
AI-powered analysis for quick understanding
An attacker can gain unauthorized access to the admin features of the SourceCodester Web-based Pharmacy Product Management System by exploiting a flaw in the add_admin.php file, allowing them to manipulate the system remotely. This vulnerability requires no special access privileges, making it easier for attackers to exploit.
Technical Description
A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown function of the file add_admin.php. Such manipulation leads to improper authorization. The attack may be launched remotely.
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$724($500-$1K)
Vendor Response
Grade APatched in 0 days
Quick Information
Published
Mar 12, 2026
27 days ago
Last Modified
Mar 12, 2026
26 days ago