Impact
A flaw exists in the /ajax.php action delete_sales of SourceCodester Pharmacy Sales and Inventory System version 1.0. Manipulating the ID argument leads to SQL injection, allowing an attacker to read, modify, or delete data from the underlying database. The vulnerability can be triggered remotely via crafted HTTP requests, and an exploit has already been published.
Affected Systems
SourceCodester Pharmacy Sales and Inventory System 1.0 is affected. The issue is confined to the delete_sales functionality within /ajax.php, but the impact extends to any data accessible through the database connection used by the application.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Exploit probability data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring only access to the web application, and a published exploit suggests realistic risk for exposed installations.
OpenCVE Enrichment