PT-2026-38554 · Sourcecodester · Pharmacy Sales/Inventory System

Xiaozhi

·

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-8083

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Pharmacy Sales and Inventory System version 1.0
Description Remote SQL injection is possible due to the manipulation of the ID argument in the '/ajax.php?action=save user' endpoint. SQL injection is a technique where an attacker inserts malicious SQL code into a query, potentially allowing them to read or modify database data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8083

Affected Products

Pharmacy Sales/Inventory System