CVE-2026-7087: SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=savesales. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7087?
CVE-2026-7087 is classified as a critical severity vulnerability due to its potential for SQL injection, which can lead to unauthorized access and data manipulation.
How do I fix CVE-2026-7087?
To fix CVE-2026-7087, validate and sanitize user inputs within the ajax.php file to prevent SQL injection attacks.
What type of vulnerability is CVE-2026-7087?
CVE-2026-7087 is an SQL injection vulnerability that affects the SourceCodester Pharmacy Sales and Inventory System.
Which version of SourceCodester Pharmacy Sales and Inventory System is affected by CVE-2026-7087?
CVE-2026-7087 affects version 1.0 of the SourceCodester Pharmacy Sales and Inventory System.
What action should be taken if CVE-2026-7087 is exploited?
If CVE-2026-7087 is exploited, it is crucial to immediately apply security patches and review database access logs for suspicious activity.