PT-2026-35543 · Sourcecodester · Pharmacy Sales/Inventory System

Zhuque

·

Published

2026-04-27

·

Updated

2026-04-28

·

CVE-2026-7199

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7199

Affected Products

Pharmacy Sales/Inventory System