CVE-2026-6189 | SourceCodester Pharmacy Sales and Inventory System 1.0 /ajax.php?action=login Username sql injection
A vulnerability described as critical has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Such manipulation of the argument Username leads to sql injection.
This vulnerability is referenced as CVE-2026-6189. It is possible to launch the attack remotely. Furthermore, an exploit is available.