GHSA-qg5w-7c3j-rfjcCriticalCVSS 9.8

The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote...

Published
May 19, 2026
Last Modified
May 20, 2026

🔗 CVE IDs covered (1)

📋 Description

The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body

🔗 References (4)