CVE-2026-6188: SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=deletesales. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6188?
CVE-2026-6188 has a medium severity rating of 5.5.
How do I fix CVE-2026-6188?
To fix CVE-2026-6188, ensure that input validation and parameterized queries are implemented in the ajax.php file.
What type of vulnerability is CVE-2026-6188?
CVE-2026-6188 is a SQL Injection vulnerability affecting the SourceCodester Pharmacy Sales and Inventory System.
Can CVE-2026-6188 be exploited remotely?
Yes, CVE-2026-6188 can be exploited remotely through the manipulation of the argument ID in the ajax.php file.
What is the impact of CVE-2026-6188?
The impact of CVE-2026-6188 can lead to unauthorized data access and potential database compromise.