CVE-2026-3401
CVE-2026-3401 is a low-severity vulnerability in Senior-walter Web-based Pharmacy Product Management System with a CVSS 3.x base score of 3.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-613.
Key facts
- Severity: Low (CVSS 3.x base score 3.1)
- CVSS v2: 2.1
- CVSS v4: 1.3
- EPSS exploit prediction: 0% (25th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-9134
- Weakness: CWE-613
- Affected product: Senior-walter Web-based Pharmacy Product Management System
- Published:
- Last modified:
Description
A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks.
Frequently asked questions
- What is CVE-2026-3401?
- A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks.
- How severe is CVE-2026-3401?
- CVE-2026-3401 has a CVSS 3.x base score of 3.1, rated low severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-3401 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (25th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-3401?
- CVE-2026-3401 affects Senior-walter Web-based Pharmacy Product Management System. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-3401?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-3401 have an EU (EUVD) identifier?
- Yes. CVE-2026-3401 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-9134.
- When was CVE-2026-3401 published?
- CVE-2026-3401 was published on 2026-03-02 and last updated on 2026-06-17.
References
- https://github.com/hiranerakkot/Web-based-Pharmacy-Product-Management-System/blob/main/README.md
- https://vuldb.com/?ctiid.348296
- https://vuldb.com/?id.348296
- https://vuldb.com/?submit.762795
- https://www.sourcecodester.com/
Affected products (1)
- cpe:2.3:a:senior-walter:web-based_pharmacy_product_management_system:1.0:*:*:*:*:*:*:*
More vulnerabilities in Senior-walter Web-based Pharmacy Product Management System
- CVE-2025-63712 — High (CVSS 8.8): Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module…
- CVE-2025-45997 — High (CVSS 8.6): Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can…
- CVE-2025-56274 — High (CVSS 8.1): SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows…
- CVE-2026-30573 — High (CVSS 7.5): A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is…
- CVE-2026-30576 — High (CVSS 7.5): A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php…
- CVE-2026-30575 — High (CVSS 7.5): A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php…
All CVEs affecting Senior-walter Web-based Pharmacy Product Management System →
Other CWE-613 (Insufficient Session Expiration) vulnerabilities
- CVE-2024-8888 — Critical (CVSS 10.0): An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the…
- CVE-2026-82311 — Critical (CVSS 9.8): Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions,…
- CVE-2026-84480 — Critical (CVSS 9.8): WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to…
- CVE-2026-14950 — Critical (CVSS 9.8): An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session…
- CVE-2026-46455 — Critical (CVSS 9.8): Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper…
- CVE-2026-21622 — Critical (CVSS 9.8): Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module)…
Browse all CWE-613 (Insufficient Session Expiration) vulnerabilities →