CVE-2026-7281: SourceCodester Pharmacy Sales and Inventory System index.php supplier cross site scripting
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function supplier of the file /index.php?page=supplier. Executing a manipulation of the argument Name can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7281?
CVE-2026-7281 has been classified as a high severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2026-7281?
To fix CVE-2026-7281, you should sanitize and validate all user inputs in the supplier function of index.php to prevent XSS attacks.
What systems are affected by CVE-2026-7281?
CVE-2026-7281 affects SourceCodester Pharmacy Sales and Inventory System version 1.0.
What is the nature of the vulnerability in CVE-2026-7281?
CVE-2026-7281 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by users.
Can CVE-2026-7281 be exploited remotely?
Yes, CVE-2026-7281 can be exploited remotely as it involves manipulating user inputs via web requests.