Junglewise Threat Intelligence

CVE-2026-7194: SourceCodester Pharmacy Sales and Inventory System SQL injection in ajax.php

CVE-2026-7194 · Severity: high · CVSS 7.3 · Published 2026-04-27

Technologies: SourceCodester Pharmacy Sales and Inventory System. Vendors: SourceCodester.

Executive brief

SourceCodester Pharmacy Sales and Inventory System is a web-based application used to manage pharmaceutical stock and sales. A security flaw in the system allows unauthorized individuals to manipulate database queries remotely. This could lead to the theft of sensitive pharmacy data, unauthorized changes to inventory records, or a complete loss of system control.

Technical details

A SQL injection vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0 within the '/ajax.php?action=save_product' endpoint. The root cause is the improper neutralization of the 'id' parameter before it is used in a SQL query. An unauthenticated remote attacker can exploit this by sending a specially crafted POST request containing malicious SQL commands. Successful exploitation allows for unauthorized database access, data exfiltration, and potential system compromise. A public proof-of-concept (PoC) using boolean-based blind SQL injection has been disclosed.

Affected products

  • SourceCodester Pharmacy Sales and Inventory System 1.0

Timeline

  • 2026-04-09: disclosed: Initial disclosure on GitHub by zzb1388
  • 2026-04-27: advisory: CVE published by VulDB

References

Related threats