CVE-2026-7746: SourceCodester Web-based Pharmacy Product Management System edit-admin.php sql injection
A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /productexpiry/edit-admin.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7746?
CVE-2026-7746 is considered a high severity SQL injection vulnerability.
How do I fix CVE-2026-7746?
To fix CVE-2026-7746, sanitize and validate all user inputs before processing them in SQL queries.
What systems are affected by CVE-2026-7746?
CVE-2026-7746 affects version 1.0 of the SourceCodester Web-based Pharmacy Product Management System.
What type of vulnerability is CVE-2026-7746?
CVE-2026-7746 is classified as an SQL injection vulnerability.
Can CVE-2026-7746 lead to data exposure?
Yes, CVE-2026-7746 can lead to unauthorized access and potential exposure of sensitive data in the database.