Loading market data...
← Back to CVE feed

CVE-2026-7392

MEDIUM CVSS 6.3 View on NVD ↗

Description

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Published: Apr 29, 2026 17:16 UTC Modified: Apr 29, 2026 21:16 UTC