CVE-2026-7129: SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /index.php?page=categories. Performing a manipulation of the argument ID results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7129?
CVE-2026-7129 is considered a high-severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-7129?
To fix CVE-2026-7129, validate and sanitize all user inputs on the index.php page to prevent XSS vulnerabilities.
What systems are affected by CVE-2026-7129?
CVE-2026-7129 affects version 1.0 of the SourceCodester Pharmacy Sales and Inventory System.
What type of vulnerability is CVE-2026-7129?
CVE-2026-7129 is identified as a cross-site scripting (XSS) vulnerability.
Can CVE-2026-7129 be exploited remotely?
Yes, CVE-2026-7129 can be exploited remotely by manipulating URL parameters.