Impact
A weakness was discovered in the function handling the /ajax.php?action=save_product request of SourceCodester Pharmacy Sales and Inventory System 1.0. By manipulating the ID argument, an attacker can inject arbitrary SQL statements, leading to unauthorized data exposure or modification. The vulnerability is exploitable remotely and a public exploit is available, meaning an attacker can trigger it over the internet without local access.
Affected Systems
The vulnerable module resides in SourceCodester Pharmacy Sales and Inventory System version 1.0. No other versions or product variations are listed as affected.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate risk level. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, as the flaw operates over a web interface. Without remediation, an attacker could exploit the injection to read, modify, or delete database contents related to pharmacy sales and inventory, potentially compromising business operations and confidential customer data.
OpenCVE Enrichment