在 CodeAstro Simple Pharmacy Management System 1.0 中发现了一个漏洞。该问题影响对文件 /SimplePharmacy-PHP/product/delete.php 中 ID 参数的某种未知处理过程。通过对 ID 参数的篡改可导致 SQL 注入。此攻击可由远程发起,相关利用代码已在公开渠道发布,可能被攻击者实际使用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CodeAstro | Simple Pharmacy Management System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CodeAstro | Simple Pharmacy Management System | 1.0 |
cpe:2.3:a:codeastro:simple_pharmacy_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104613 | 6.3 MEDIUM | CodeAstro Simple Pharmacy Management System view.php sql injection |
| CVE-2026-104625 | 6.3 MEDIUM | CodeAstro Simple Loan Management System index.php sql injection |
No comments yet