CVE-2026-6188 | SourceCodester Pharmacy Sales and Inventory System 1.0 ajax.php?action=delete_sales ID sql injection
A vulnerability marked as critical has been reported in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. This manipulation of the argument ID causes sql injection.
The identification of this vulnerability is CVE-2026-6188. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.