← Terug naar overzicht

A critical vulnerability has been identified in itsourcecode Online Pharmacy System version 1.0. The flaw exists in the move_uploaded_file function within the file all_users/register.php, part of the User Registration component. By manipulating the 'photo' argument, an attacker can perform an unrestricted file upload, potentially uploading malicious files to the server. The attack can be launched remotely without requiring physical access. A public exploit has already been published and is available for use, increasing the risk of active exploitation. This type of vulnerability can lead to remote code execution if a malicious file such as a web shell is uploaded. The affected product is a web-based pharmacy management system commonly used for educational or small-scale deployments. Immediate patching or mitigation is strongly advised.

Affected products

  • itsourcecode Online Pharmacy System 1.0

Related CVE's

  • CVE-2026-78245

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities