SQL Injection Vulnerability in Sourcecodester Pharmacy Point of Sale System
CVE-2026-26708
9.8CRITICAL
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 2 March 2026
What is CVE-2026-26708?
The Sourcecodester Pharmacy Point of Sale System version 1.0 is susceptible to SQL Injection attacks through the manage_user.php endpoint. This vulnerability allows attackers to manipulate database queries, potentially leading to unauthorized access to sensitive data and database exploitation. It is crucial for users of this system to implement immediate security measures to mitigate the risk.
