A SQL injection vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw exists in the Customer::cusAuthentication function within the /login.php file of the Customer Login Interface component. Attackers can manipulate the U_USERNAME argument to perform SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been released, increasing the risk of active exploitation. Successful exploitation could allow attackers to bypass authentication and gain unauthorized access. The vulnerability is tracked under CVE-2026-82611 and has been assigned a high criticality rating.