PT-2026-38554 · Sourcecodester · Pharmacy Sales/Inventory System

Xiaozhi

·

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-8083

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save user. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-8083

Affected Products

Pharmacy Sales/Inventory System