5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2026-7392
Source
VulDB
Published
Apr 29, 2026 at 16:45
Affected Product
Vendor
SourceCodester
Product
Pharmacy Sales and Inventory System
Version
1.0
Affected Versions
SourceCodester Pharmacy Sales and Inventory System 1.0