Sceawere

Vulnerability Detail

CVE-2026-104614UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Simple Pharmacy

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
9h ago
Vendor
CodeAstro
Product
Simple Pharmacy Management System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-02T14:17:09.990Z",
  "pubdate": "2026-10-02T14:17:09.990Z",
  "executiveSummary": "A critical SQL injection vulnerability exists in CodeAstro Simple Pharmacy Management System 1.0. The vulnerability resides within the file /SimplePharmacy-PHP/product/delete.php and is triggered via improper neutralization of input passed to the ID argument.\nThis flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands against the backend database. Successful exploitation grants attackers the ability to bypass security controls, manipulate sensitive pharmacy data, or potentially achieve full database compromise.\nGiven that exploit code is publicly available, the risk to affected deployments is high, as the vulnerability can be leveraged by external threat actors without requiring prior system authentication. The exposure of the database layer presents significant data confidentiality, integrity, and availability risks.",
  "technicalDetails": "The vulnerability is classified as an SQL injection arising from the failure of the /SimplePharmacy-PHP/product/delete.php script to properly validate or sanitize user-supplied input provided to the ID parameter. In the context of this application, the ID parameter is directly incorporated into a SQL query string used to perform delete operations on product entries.\nThe root cause is the lack of parameterized queries or prepared statements when handling the ID argument. By injecting malicious SQL syntax into this parameter, an attacker can alter the logic of the underlying query, allowing for unauthorized data manipulation or information extraction.\nThe attack flow follows a predictable pattern: an attacker sends a crafted HTTP request to the web server, targeting the vulnerable delete.php file. The attacker appends SQL metacharacters (such as single quotes, comments, or logical operators like 'OR 1=1') to the ID parameter value. Since the application fails to use query parameterization, the database engine interprets the injected strings as executable commands rather than literal data. For example, an attacker might manipulate the ID parameter to force the deletion of unintended rows or extract data from other tables through UNION-based techniques.\nThis vulnerability is remotely exploitable and does not explicitly require authenticated access to the application, depending on the specific server configuration. The impact of this injection extends beyond the deletion of records; depending on the permissions of the database user account utilized by the application, an attacker could extract sensitive system information, perform administrative database functions, or in some configurations, execute arbitrary commands on the underlying host operating system if stacked queries are enabled and the database driver supports them.\nThe affected component is the product deletion module within the Simple Pharmacy Management System version 1.0. The susceptibility is directly linked to the server-side code's handling of the ID argument, which lacks the necessary input filtering mechanisms to prevent the execution of arbitrary SQL syntax."
}
CVE-2026-104614: SQL Injection in Simple Pharmacy (MEDIUM Severity, CVSS: 6.3) | Sceawere