CVE-2026-7391: SourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function savesupplier of the file /ajax.php?action=savesupplier. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7391?
CVE-2026-7391 has been classified as a critical vulnerability due to its potential to allow SQL injection attacks.
How do I fix CVE-2026-7391?
To remediate CVE-2026-7391, ensure that proper input validation and parameterized queries are implemented in the save_supplier function of ajax.php.
What systems are affected by CVE-2026-7391?
CVE-2026-7391 specifically affects version 1.0 of the SourceCodester Pharmacy Sales and Inventory System.
What kind of attack is CVE-2026-7391 associated with?
CVE-2026-7391 is associated with SQL injection attacks that can manipulate database queries and expose sensitive data.
Can CVE-2026-7391 lead to data breaches?
Yes, if exploited, CVE-2026-7391 can lead to unauthorized access to and potential disclosure of sensitive information within the database.