CVE-2026-104613: CodeAstro Simple Pharmacy Management System view.php sql injection
A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be initiated remotely, but the severity vector indicates that the attacker needs low-level privileges. No user interaction is required.
Which component should be investigated?
The affected endpoint is /SimplePharmacy-PHP/product/view.php, specifically its ID argument. The issue is reported in CodeAstro Simple Pharmacy Management System 1.0.
How mature is exploitation?
A public exploit has been disclosed and may be used. The supplied assessment rates exploit maturity as proof-of-concept.