A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is not a standalone exploit script but a vulnerable copy of SourceCodester Pharmacy Sales and Inventory System 1.0 packaged to demonstrate SQL injection issues, especially CVE-2026-7392. The top-level files and the duplicated pharmacy_source/ tree both contain the vulnerable PHP application. The core issue is in admin_class.php, where nearly every handler uses extract($_POST) and directly concatenates attacker-controlled values into SQL statements. ajax.php acts as the dispatcher, routing action names from GET to backend methods such as login, delete_supplier, delete_product, delete_sales, delete_category, save_* and delete_* operations. Main exploit capability: unauthenticated or weakly protected web SQL injection against multiple AJAX actions. The README explicitly identifies /ajax.php?action=delete_supplier with POST parameter id as CVE-2026-7392. Code review confirms the pattern is widespread: login() concatenates username/password into a SELECT; delete_category(), delete_type(), delete_sales(), delete_expired() and similar methods concatenate id directly into DELETE statements; save/update methods concatenate form fields into INSERT/UPDATE queries. This means the repository demonstrates not just one sink but a broad insecure CRUD surface that can support authentication bypass, arbitrary row deletion, data tampering, and potentially broader SQL abuse depending on DB permissions. Repository structure: most files are the vulnerable web app itself, plus bundled third-party frontend assets (DataTables, Font Awesome, Select2, CSS). The meaningful exploit-relevant files are README.md, admin_class.php, ajax.php, db_connect.php, login.php, index.php, and the pharmacy_source/*.php pages that invoke the AJAX actions. database/pharmacy_db.sql provides the schema and sample data, including the local DB name pharmacy_db. No exploit framework is used, and no weaponized payload or automated exploitation logic is present; this is best classified as a POC/vulnerable application snapshot rather than a polished exploit tool.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.