CVE-2026-7126
A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_category. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
View on NVDAnalysis
This vulnerability affects a niche script from SourceCodester, which is primarily used for educational or hobby purposes rather than professional production environments. While it is a remote SQL injection with a public exploit, the product is not relevant to the MexicoDev community's professional stack.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LCWE-74CWE-89EPSS
Technical description
A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_category. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.