CVE-2026-10248: Sourcecodester Pharmacy Sales And Inventory System
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of the component Supplier Creation Interface. This manipulation of the argument Address/Company Name causes csv injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected products
- Sourcecodester Pharmacy Sales And Inventory System: version 1.0 only
Published 2026-06-01. Last modified 2026-07-22.