A vulnerability, which was classified as critical, has been found in SourceCodester Pharmacy Product Management System 1.0. This affects an unknown part of the file add-sales.php of the component POST Parameter Handler. Performing a manipulation of the argument txtqty results in business logic errors.

This vulnerability is cataloged as CVE-2026-5812. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.