


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /aj…
Published:
26 April 2026 at 22:00:00
Alert date:
27 April 2026 at 15:02:20
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability has been identified in SourceCodester Pharmacy Sales and Inventory System version 1.0. The vulnerability exists in the /ajax.php file with the save_type action, where manipulation of the ID argument leads to SQL injection. The attack can be executed remotely and the exploit has been publicly disclosed. This affects unknown processing within the application and poses a significant security risk due to the remote attack vector and public availability of the exploit.
Technical details
Mitigation steps:
Affected products:
SourceCodester Pharmacy Sales and Inventory System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7128
https://github.com/lonelyuan/vunls/issues/13
https://vuldb.com/submit/800973
https://vuldb.com/vuln/359727
https://vuldb.com/vuln/359727/cti
https://www.sourcecodester.com/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
