SourceCodester Pharmacy Sales and Inventory System是SourceCodester开源的一个药品销售和库存系统。 SourceCodester Pharmacy Sales and Inventory System 1.0版本存在注入漏洞,该漏洞源于文件/ajax.php?action=save_sales中未知函数对参数ID操作不当,可能导致SQL注入。攻击者可能远程发起攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | Pharmacy Sales and Inventory System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Pharmacy Sales and Inventory System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7088 | 7.3 HIGH | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
| CVE-2026-7126 | 7.3 HIGH | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
| CVE-2026-7127 | 7.3 HIGH | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
| CVE-2026-7128 | 7.3 HIGH | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
| CVE-2026-7130 | 7.3 HIGH | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
| CVE-2026-7194 | 7.3 HIGH | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
| CVE-2026-7199 | 7.3 HIGH | SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection |
| CVE-2026-7129 | 4.3 MEDIUM | SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting |
| CVE-2026-7200 | 4.3 MEDIUM | SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting |
No comments yet