CVE-2026-7088: SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=savereceiving. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7088?
CVE-2026-7088 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2026-7088?
To fix CVE-2026-7088, ensure that all user-inputted data is properly validated and sanitized in the /ajax.php?action=save_receiving function.
What are the potential impacts of CVE-2026-7088?
The potential impacts of CVE-2026-7088 include unauthorized database access and data manipulation.
Who is affected by CVE-2026-7088?
CVE-2026-7088 affects users of the SourceCodester Pharmacy Sales and Inventory System version 1.0.
Is there a patch available for CVE-2026-7088?
As of now, there is no official patch available for CVE-2026-7088, but users should apply coding best practices to mitigate the risk.