CVE-2026-26887: SQL Injection
Published Mar 3, 2026
·Updated
Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/managesupplier.php.
Affected Software
2 affected components
Sourcecodester Pharmacy Point of Sale System
oretnom23 Pharmacy Point Of Sale System=1.0
Event History
Mar 3, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26887?
CVE-2026-26887 is classified as a high-severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2026-26887?
To fix CVE-2026-26887, validate and sanitize all user inputs on the /pharmacy/manage_supplier.php page to prevent SQL injection.
3
What type of attack does CVE-2026-26887 allow?
CVE-2026-26887 allows attackers to perform SQL injection attacks which can lead to unauthorized access to sensitive database information.
4
What software is affected by CVE-2026-26887?
CVE-2026-26887 affects Sourcecodester Pharmacy Point of Sale System version 1.0.
5
Is it safe to use Sourcecodester Pharmacy Point of Sale System with CVE-2026-26887?
It is not safe to use Sourcecodester Pharmacy Point of Sale System without applying the necessary security fixes for CVE-2026-26887.