SQL Injection Flaw in Pharmacy Point of Sale System by sourcecodester
CVE-2026-26706
9.8CRITICAL
Key Information:
- Vendor
sourcecodester
- Vendor
- CVE Published:
- 2 March 2026
What is CVE-2026-26706?
The Pharmacy Point of Sale System version 1.0, developed by sourcecodester, is vulnerable to SQL Injection attacks through the /pharmacy/view_receipt.php endpoint. This vulnerability allows attackers to execute arbitrary SQL queries, potentially leading to unauthorized access to sensitive data, manipulation of the database, or other harmful impacts.
