CVE-2026-7128: SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=savetype. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7128?
CVE-2026-7128 is a high severity SQL injection vulnerability affecting SourceCodester Pharmacy Sales and Inventory System 1.0.
How do I fix CVE-2026-7128?
To fix CVE-2026-7128, you should sanitize and validate all user inputs in the ajax.php file to prevent SQL injection.
What version of SourceCodester Pharmacy Sales and Inventory System is affected by CVE-2026-7128?
CVE-2026-7128 affects version 1.0 of the SourceCodester Pharmacy Sales and Inventory System.
What file is vulnerable in CVE-2026-7128?
The vulnerable file in CVE-2026-7128 is /ajax.php, specifically when processing the 'action=save_type' parameter.
What type of attack can occur due to CVE-2026-7128?
CVE-2026-7128 can allow an attacker to execute arbitrary SQL queries on the database, leading to data compromise.