A SQL injection vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw resides in the Order::pupdate function within the file /rider/orders/controller.php?action=edit&actions=confirm, part of the Order Status Update component. Attackers can manipulate the 'ID' argument to perform SQL injection attacks remotely without requiring physical access. The exploit has been publicly disclosed, increasing the risk of active exploitation. This type of vulnerability can allow attackers to read, modify, or delete database contents, potentially exposing sensitive patient and order data. The vulnerability is tracked as CVE-2026-85187 and is listed on NVD and VulDB. No patch information is currently noted. Given its remote exploitability and public disclosure, this represents a high-severity risk for deployments of this system.