


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=delete_customer. …
Published:
30 April 2026 at 22:00:00
Alert date:
1 May 2026 at 16:05:43
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability has been discovered in SourceCodester Pharmacy Sales and Inventory System version 1.0. The flaw exists in the /ajax.php file's delete_customer action, where the ID parameter can be manipulated to perform SQL injection attacks. The vulnerability can be exploited remotely and a public exploit has been published, making it actively exploitable. This affects the customer deletion functionality of the pharmacy management system.
Technical details
Mitigation steps:
Affected products:
SourceCodester Pharmacy Sales and Inventory System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7549
https://github.com/khairulazly760530-cell/cves/issues/3
https://vuldb.com/submit/805538
https://vuldb.com/vuln/360359
https://vuldb.com/vuln/360359/cti
https://www.sourcecodester.com/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
