SQL Injection Vulnerability in Pharmacy Point of Sale System by Sourcecodester
CVE-2026-26705
9.8CRITICAL
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 2 March 2026
What is CVE-2026-26705?
The Pharmacy Point of Sale System v1.0 by Sourcecodester contains a vulnerability that allows attackers to exploit SQL injection in the /pharmacy/view_product.php file, potentially leading to unauthorized access to sensitive data. This allows an attacker to manipulate the database in unintended ways, compromising the integrity and confidentiality of the application.
