PT-2026-35732 · Sourcecodester · Pharmacy Sales/Inventory System

Test-User

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7282

CVSS v3.1

4.7

Medium

AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete expired of the file /ajax.php?action=delete expired. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-7282

Affected Products

Pharmacy Sales/Inventory System