CVE-2026-104614: CodeAstro Simple Pharmacy Management System delete.php sql injection
A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs low-level privileges but does not need user interaction. Exploitation can be performed remotely by manipulating the ID argument handled by /SimplePharmacy-PHP/product/delete.php.
Is public exploit code available?
Yes. The exploit is publicly available, so organizations running the affected CodeAstro Simple Pharmacy Management System 1.0 should assume exploitation may be practical.
What is the potential impact of successful exploitation?
The supplied severity vector indicates low impacts to confidentiality, integrity, and availability. The issue is SQL injection, which may allow an authenticated low-privilege attacker to affect database operations through the vulnerable delete endpoint.