CVE-2026-7130 | SourceCodester Pharmacy Sales and Inventory System 1.0 ajax.php?action=delete_category ID sql injection
A vulnerability described as critical has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_category. Executing a manipulation of the argument ID can lead to sql injection.
This vulnerability appears as CVE-2026-7130. The attack may be performed from remote. In addition, an exploit is available.