PT-2026-36791 · Sourcecodester · Web-Based Pharmacy Product Management System

Mjh_123

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-7746

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /product expiry/edit-admin.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7746

Affected Products

Web-Based Pharmacy Product Management System