← Back to overview

A SQL injection vulnerability (CVE-2026-82614) has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw resides in the loadResultList function within the Product Category Filter Interface, accessible via /index.php?q=product. Attackers can manipulate the 'Category' argument to inject malicious SQL queries. The attack can be launched remotely without requiring physical access. A working exploit has been publicly published, increasing the risk of active exploitation. The vulnerability poses a significant risk to any organization running this software as it could lead to unauthorized database access or data exfiltration. No patch information is currently noted in the article.

Affected products

  • itsourcecode Online Medicine Delivery System 1.0

Related CVE's

  • CVE-2026-82614

Categories

  • Database & Storage
  • Web Technologies