Description
A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: SQL injection permitting remote data disclosure or modification
Action: Assess Impact
AI Analysis

Impact

A vulnerability in the CodeAstro Simple Pharmacy Management System, specifically in the product/view.php file, allows an attacker to manipulate the ID parameter and inject raw SQL. The flaw is an unsanitized input that can be leveraged to execute arbitrary database queries, potentially exposing sensitive pharmacy records or altering them. This consequence directly compromises confidentiality and integrity of the system’s data.

Affected Systems

The affected product is CodeAstro Simple Pharmacy Management System, version 1.0. The vulnerability resides in the view.php component that handles product display; no other versions or components were identified from the available data.

Risk and Exploitability

The CVSS score is 5.3, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack is remote, driven by crafted input to the ID argument, and the exploit has already been publicly disclosed. While the likelihood of exploitation is uncertain without EPSS data, the mere existence of a publicly known SQL injection warrants attention.

Generated by OpenCVE AI on October 2, 2026 at 15:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the pharmacy management system to a patched version that validates and sanitizes the ID parameter.
  • If a patch is unavailable, restrict access to product/view.php through network controls or rewrite the code to use prepared statements and parameterized queries for all database interactions.
  • Apply firewall or segment the network to limit direct external access to the application endpoints, reducing the attack surface.
  • Enable logging and monitoring for suspicious query patterns and alert on repeated injection attempts.

Generated by OpenCVE AI on October 2, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Title CodeAstro Simple Pharmacy Management System view.php sql injection
First Time appeared Codeastro
Codeastro simple Pharmacy Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:codeastro:simple_pharmacy_management_system:*:*:*:*:*:*:*:*
Vendors & Products Codeastro
Codeastro simple Pharmacy Management System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Codeastro Simple Pharmacy Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-02T15:14:45.220Z

Reserved: 2026-10-02T04:17:53.252Z

Link: CVE-2026-104613

cve-icon Vulnrichment

Updated: 2026-10-02T15:14:16.275Z

cve-icon NVD

Status : Received

Published: 2026-10-02T14:17:09.807

Modified: 2026-10-02T16:16:46.593

Link: CVE-2026-104613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:15:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')