PT-2026-35958 · Sourcecodester · Pharmacy Sales/Inventory System

Microwave

·

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-7392

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete supplier of the file /ajax.php?action=delete supplier. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7392

Affected Products

Pharmacy Sales/Inventory System