CVE-2026-6187: SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=chkprodavailability. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6187?
The severity of CVE-2026-6187 is classified as medium with a score of 5.5.
What type of vulnerability is CVE-2026-6187?
CVE-2026-6187 is a SQL injection vulnerability found in the SourceCodester Pharmacy Sales and Inventory System.
How do I fix CVE-2026-6187?
To mitigate CVE-2026-6187, ensure proper parameterized queries are implemented in the /ajax.php?action=chk_prod_availability file to prevent SQL injection.
Can CVE-2026-6187 be exploited remotely?
Yes, CVE-2026-6187 can be exploited remotely by manipulating the ID argument.
Which software is affected by CVE-2026-6187?
CVE-2026-6187 affects SourceCodester Pharmacy Sales and Inventory System version 1.0.