


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_ca…
Published:
26 april 2026 om 22:00:00
Alert date:
27 april 2026 om 15:02:20
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A SQL injection vulnerability has been discovered in SourceCodester Pharmacy Sales and Inventory System version 1.0. The flaw affects the /ajax.php file with the save_category action, where manipulation of the ID parameter leads to SQL injection. The vulnerability can be exploited remotely and public exploits are available, making it actively exploitable. This represents a high-risk security issue for affected pharmacy management systems.
Technical details
Mitigation steps:
Affected products:
SourceCodester Pharmacy Sales and Inventory System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7126
https://github.com/y1shiny1shin/vuldb-project/issues/2
https://vuldb.com/submit/800971
https://vuldb.com/vuln/359725
https://vuldb.com/vuln/359725/cti
https://www.sourcecodester.com/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
