Impact
A SQL injection flaw exists in the delete product functionality of SourceCodester Pharmacy Sales and Inventory System 1.0. An attacker can manipulate the ID parameter sent to /ajax.php?action=delete_product to inject arbitrary SQL statements. This allows unauthorized read, modification or deletion of database contents, compromising confidentiality, integrity and possibly availability.
Affected Systems
The vulnerability affects the SourceCodester Pharmacy Sales and Inventory System version 1.0. No other versions or variants are listed. The flaw resides in a publicly accessible ajax endpoint and would impact any installation that has not been updated or patched.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS is not available, and the issue is not currently listed in the CISA KEV catalog. However, the flaw is exploitable over the network through a standard HTTP request, and the public exploit code mentioned in the advisories suggests that it is likely in use or easy to replicate. Because no restrictions on the target are specified, any remotely reachable instance could be targeted, increasing the risk for hosted environments.
OpenCVE Enrichment