CVE-2026-7127: SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=deletereceiving. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7127?
CVE-2026-7127 has a high severity rating due to its exploitation potential allowing SQL injection.
How do I fix CVE-2026-7127?
To fix CVE-2026-7127, validate and sanitize all user input in the ajax.php file, especially in the ID parameter.
What systems are affected by CVE-2026-7127?
CVE-2026-7127 affects SourceCodester Pharmacy Sales and Inventory System version 1.0.
What kind of attack does CVE-2026-7127 enable?
CVE-2026-7127 enables attackers to perform SQL injection attacks, allowing unauthorized access to the database.
Can CVE-2026-7127 be exploited remotely?
Yes, CVE-2026-7127 can be exploited remotely by attackers with access to the targeted system's ajax.php endpoint.