CVE-2026-6189: SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6189?
CVE-2026-6189 has a medium severity rating of 5.5.
How do I fix CVE-2026-6189?
To fix CVE-2026-6189, you should implement prepared statements or parameterized queries in the affected ajax.php file to prevent SQL injection.
What is the impact of exploiting CVE-2026-6189?
Exploiting CVE-2026-6189 can allow an attacker to perform SQL injection, potentially leading to unauthorized access to the database.
Which software is affected by CVE-2026-6189?
CVE-2026-6189 affects version 1.0 of the SourceCodester Pharmacy Sales and Inventory System.
Is CVE-2026-6189 remotely exploitable?
Yes, CVE-2026-6189 can be exploited remotely, making it a significant security concern.