CVE-2026-31071 Details
Description
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserData, modify drug inventory, and access private medical prescription data via /api/doctorOder.
A vulnerability exists in the LalanaChami Pharmacy Management System in commit 5c3d028, where API endpoints lack authentication middleware. This flaw allows unauthenticated remote attackers to access sensitive data and modify inventory. Exploitation can lead to unauthorized access to user records, including bcrypt password hashes, through the /api/user/getUserData endpoint. Additionally, attackers can alter drug inventory and retrieve private medical prescription data via the /api/doctorOder endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2026CISA-ADP
Assessed May 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/nedlir/bc8ad4693c53256819280e8f5de49286 | CISA-ADP | ExploitRemedyTechnical Analysis |
| https://gist.github.com/nedlir/bc8ad4693c53256819280e8f5de49286 | [email protected] | ExploitRemedyTechnical Analysis |
| https://github.com/LalanaChami/Pharmacy-Mangment-System/tree/5c3d02888631166649856f71d542387114b3010b/backend/routes | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| LalanaChami Pharmacy Management System | 5c3d028c520628ece50f034900e0a98c07943d70 0.0.0 (semver) 8.3.6 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | [email protected] |
Volerion