CVE-2026-26704: SQL Injection
Published Mar 2, 2026
·Updated
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/viewcategory.php.
Affected Software
2 affected components
Sourcecodester Pharmacy Point of Sale System
oretnom23 Pharmacy Point Of Sale System=1.0
Event History
Mar 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 27, 58142
Event
via FIRST·08:04 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-26704?
CVE-2026-26704 is classified as a high severity vulnerability due to its potential for SQL Injection.
2
How do I fix CVE-2026-26704?
To fix CVE-2026-26704, ensure proper parameterized queries and input validation are implemented in /pharmacy/view_category.php.
3
What type of vulnerability is CVE-2026-26704?
CVE-2026-26704 is a SQL Injection vulnerability allowing an attacker to manipulate database queries.
4
Which software versions are affected by CVE-2026-26704?
CVE-2026-26704 affects version 1.0 of the sourcecodester Pharmacy Point of Sale System.
5
What impact can CVE-2026-26704 have on the system?
Exploitation of CVE-2026-26704 can lead to unauthorized data access and modification in the database.