Sploitus

CVE-2026-7392

1 known exploit for CVE-2026-7392

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Fix
Available
CVSS 2.0
6.5 MEDIUM
CVSS 3.1
6.3 MEDIUM
EPSS
0.2% (9th percentile)
Weakness
CWE-74, CWE-89
NVD status
Deferred
Published
2026-04-29
CVE-2026-7392 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-7392

Proof-of-concept code and exploit modules indexed by Sploitus