


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?acti…
Published:
26 April 2026 at 22:00:00
Alert date:
27 April 2026 at 19:18:12
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. The vulnerability exists in the /ajax.php file with the save_receiving action, where manipulation of the ID argument leads to SQL injection. The attack can be launched remotely and exploits have been made publicly available. This represents a high-risk vulnerability due to the public availability of exploits and remote attack capability.
Technical details
Mitigation steps:
Affected products:
SourceCodester Pharmacy Sales and Inventory System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7088
https://github.com/nidieaaa/test/issues/3
https://vuldb.com/submit/800062
https://vuldb.com/vuln/359663
https://vuldb.com/vuln/359663/cti
https://www.sourcecodester.com/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
