The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body
Metrics
Affected Vendors & Products
References
History
Wed, 20 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Administrator Role Assignment in LalanaChami Pharmacy Management System | |
| Weaknesses | CWE-284 CWE-285 |
Wed, 20 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
cvssV3_1
|
Wed, 20 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lalanachami
Lalanachami pharmacy Management System |
|
| Vendors & Products |
Lalanachami
Lalanachami pharmacy Management System |
Tue, 19 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Administrator Role Assignment in LalanaChami Pharmacy Management System | |
| Weaknesses | CWE-284 CWE-285 |
Tue, 19 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/signup endpoint fails to validate the role parameter in the request body | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-05-19T00:00:00.000Z
Updated: 2026-05-20T13:55:31.179Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-31070
Updated: 2026-05-20T13:55:26.269Z
Status : Deferred
Published: 2026-05-19T16:16:20.363
Modified: 2026-05-20T14:16:40.350
Link: CVE-2026-31070
No data.