{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/online-pharmacy-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-78245"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Online Pharmacy System (1.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","remote-code-execution","cve-2026-78245"],"_cs_type":"advisory","_cs_vendors":["itsourcecode"],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-78245 affects the itsourcecode Online Pharmacy System version 1.0. The vulnerability is located within the 'all_users/register.php' file, specifically in the component responsible for user registration. An attacker can manipulate the 'photo' argument passed to the 'move_uploaded_file' function, allowing for the unrestricted upload of arbitrary files to the server. Because the application fails to adequately validate or restrict the file types processed by this function, a remote, unauthenticated attacker could upload malicious scripts, such as web shells, leading to remote code execution. This vulnerability is highly critical due to the lack of required authentication, allowing exploitation by any remote actor with network access to the target application. Public exploit code has been reported, making this an immediate risk to organizations running this specific version of the software.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify systems running itsourcecode Online Pharmacy System 1.0.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the public user registration page located at /all_users/register.php.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a registration request, intercepting the HTTP request using a proxy tool.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the 'photo' parameter in the POST request to point to a malicious file, such as a PHP web shell.\u003c/li\u003e\n\u003cli\u003eThe application's 'move_uploaded_file' function processes the malicious request without validating the file extension or content.\u003c/li\u003e\n\u003cli\u003eThe web server saves the attacker-supplied file into a directory accessible by the web root.\u003c/li\u003e\n\u003cli\u003eAttacker requests the newly uploaded file via the browser to trigger execution of the malicious script.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote command execution with the privileges of the web server service account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated attacker to gain remote code execution on the underlying server. This can lead to full system compromise, data theft, ransomware deployment, or use of the server as a pivot point for further lateral movement within the target organization's network. Given the nature of the application as a pharmacy management system, the potential exposure of sensitive patient and operational data is significant.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy a web application firewall (WAF) rule to inspect and block requests to '/all_users/register.php' that contain suspicious file extensions (e.g., .php, .php5, .phtml) within the 'photo' parameter.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for new file creation events within the web directory where user-uploaded photos are stored.\u003c/li\u003e\n\u003cli\u003eAudit the web server configuration to ensure that file execution permissions are restricted in user upload directories.\u003c/li\u003e\n\u003cli\u003eIdentify and decommission any production instances of 'Online Pharmacy System' 1.0 until a security patch is provided by the vendor.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T11:56:18Z","date_published":"2026-08-24T11:56:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-online-pharmacy-rce/","summary":"An unauthenticated remote code execution vulnerability (CVE-2026-78245) exists in itsourcecode Online Pharmacy System 1.0 due to improper file validation within the user registration process.","title":"Unrestricted File Upload Vulnerability in itsourcecode Online Pharmacy System","url":"https://feed.craftedsignal.io/briefs/2026-08-online-pharmacy-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Online Pharmacy System (1.0)","version":"https://jsonfeed.org/version/1.1"}