5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expired. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Basic Information
ID
CVE-2026-7282
Source
VulDB
Published
Apr 28, 2026 at 13:30
Affected Product
Vendor
SourceCodester
Product
Pharmacy Sales and Inventory System
Version
1.0
Affected Versions
SourceCodester Pharmacy Sales and Inventory System 1.0