CVE-2026-7283: SourceCodester Pharmacy Sales and Inventory System ajax.php save_expired sql injection
A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function saveexpired of the file /ajax.php?action=saveexpired. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7283?
CVE-2026-7283 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2026-7283?
To fix CVE-2026-7283, sanitize and validate all user inputs before processing them in the save_expired function.
What are the potential impacts of CVE-2026-7283?
CVE-2026-7283 can allow attackers to execute arbitrary SQL queries, potentially compromising the database.
Is CVE-2026-7283 exploited in the wild?
There have been indications that CVE-2026-7283 is susceptible to exploitation, making immediate mitigation necessary.
Which software versions are affected by CVE-2026-7283?
CVE-2026-7283 affects SourceCodester Pharmacy Sales and Inventory System version 1.0.