PT-2026-35430 · Sourcecodester · Pharmacy Sales/Inventory System

Christychen11

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7128

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Pharmacy Sales and Inventory System version 1.0
Description An issue exists where improper processing of the '/ajax.php?action=save type' endpoint allows for remote SQL injection. This occurs through the manipulation of the ID argument. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to or modification of the database.
Recommendations Update SourceCodester Pharmacy Sales and Inventory System to a version newer than 1.0. As a temporary workaround, restrict access to the '/ajax.php?action=save type' endpoint or avoid using the ID parameter until a patch is applied.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-7128

Affected Products

Pharmacy Sales/Inventory System