Skip to content
CVSS 7.3 · HIGH

CVE-2026-7126

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_category. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

View on NVD

Analysis

This vulnerability affects a niche script from SourceCodester, which is primarily used for educational or hobby purposes rather than professional production environments. While it is a remote SQL injection with a public exploit, the product is not relevant to the MexicoDev community's professional stack.

Severity

Score: 7.3(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: LOW
I: LOW
A: LOW
Weakness (CWE): CWE-74CWE-89

EPSS

Probability of exploitation (next 30 days): 0.0004 (0.0%)
Percentile: 11.7%
EPSS: 2026-05-06

Technical description

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_category. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

Published: 4/27/2026, 2:16:56 PM
Last modified: 4/29/2026, 1:00:01 AM

References

HomeEventsBlogResourcesTeam