Impact
The vulnerability resides in the /ajax.php?action=delete_customer endpoint of SourceCodester Pharmacy Sales and Inventory System 1.0, where the ID parameter is not properly sanitized. An attacker who can influence this parameter can inject arbitrary SQL statements, enabling unauthorized read or write operations on the underlying database. The weakness corresponds to CWE-74 and CWE-89, representing code injection and unsafe use of database calls.
Affected Systems
SourceCodester Pharmacy Sales and Inventory System version 1.0. No other affected versions are publicly documented.
Risk and Exploitability
The publicly available CVSS score of 6.9 suggests a significant risk. Because the vulnerability is exploitable remotely, an attacker with network access could trigger the injection without authentication. The EPSS score is not available, so exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA KEV. The published exploit indicates that attackers can inject arbitrary SQL commands and possibly gain full database compromise.
OpenCVE Enrichment