Junglewise Threat Intelligence

CVE-2026-6188: SourceCodester Pharmacy Sales and Inventory System SQL injection in ajax.php

CVE-2026-6188 · Severity: high · CVSS 7.3 · Published 2026-04-13

Technologies: SourceCodester Pharmacy Sales and Inventory System. Vendors: SourceCodester.

Executive brief

SourceCodester Pharmacy Sales and Inventory System is a web-based application used to manage pharmaceutical stock and sales records. A security flaw in the system allows remote attackers to interfere with the database without needing a username or password. This could lead to the theft of sensitive business data, unauthorized modification of inventory records, or complete loss of system data.

Technical details

A SQL injection vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0 within the '/ajax.php?action=delete_sales' endpoint. The root cause is the failure to sanitize or validate the 'id' parameter before it is used in a SQL query. An attacker can exploit this by sending a specially crafted POST request containing malicious SQL commands. This is a boolean-based blind SQL injection that does not require authentication. Successful exploitation allows for unauthorized database access, sensitive data extraction, and data tampering. A public exploit (PoC) using sqlmap has been disclosed.

Affected products

  • SourceCodester Pharmacy Sales and Inventory System 1.0

Timeline

  • 2026-04-05: disclosed: Vulnerability discovered and reported on GitHub by zzb1388
  • 2026-04-13: advisory: CVE-2026-6188 published

References