A vulnerability classified as critical was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function save_expired of the file /ajax.php?action=save_expired. The manipulation of the argument ID results in sql injection.

This vulnerability is known as CVE-2026-7283. It is possible to launch the attack remotely. Furthermore, an exploit is available.