Description
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=chk_prod_availability. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
Published: 2026-04-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL injection allowing data exposure and modification
Action: Patch Immediately
AI Analysis

Impact

The flaw is an unsanitized "ID" parameter in the /ajax.php?action=chk_prod_availability endpoint of SourceCodester Pharmacy Sales and Inventory System 1.0. By injecting malicious SQL through this argument, an attacker can execute arbitrary database commands. The vulnerability is exploitable from the internet and a public exploit is available, meaning an attacker can read, modify, or delete inventory, pricing, and transaction records. The single compromised record could lead to full system compromise, loss of integrity and confidentiality.

Affected Systems

SourceCodester Pharmacy Sales and Inventory System version 1.0 is affected. No other affected versions are listed. The vulnerability is tied to the vendor’s "Pharmacy Sales and Inventory System" product.

Risk and Exploitability

The CVSS score of 6.9 indicates medium‑high impact; the lack of an EPSS score does not negate the known public exploit, suggesting a realistic threat. The CVE is not included in the CISA KEV list, but attackers can easily trigger it over the network with a crafted request to /ajax.php?action=chk_prod_availability&ID=… to bypass authentication and gain unauthorized database access. The risk is significant for any deployment that relies on the default install.

Generated by OpenCVE AI on April 13, 2026 at 18:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a patched version as soon as it becomes available.
  • If a patch is not available, modify the code to use parameterized queries or proper input validation for the ID parameter in ajax.php.
  • Consider disabling or protecting the chk_prod_availability endpoint until a fix is applied.

Generated by OpenCVE AI on April 13, 2026 at 18:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester pharmacy Sales And Inventory System
Vendors & Products Sourcecodester
Sourcecodester pharmacy Sales And Inventory System

Tue, 14 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=chk_prod_availability. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
Title SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Pharmacy Sales And Inventory System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-14T13:54:33.214Z

Reserved: 2026-04-13T08:36:25.268Z

Link: CVE-2026-6187

cve-icon Vulnrichment

Updated: 2026-04-14T13:54:24.621Z

cve-icon NVD

Status : Deferred

Published: 2026-04-13T16:16:36.017

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-6187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:34:12Z

Weaknesses