← Terug naar overzicht

A SQL injection vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw exists in the Order::pupdate function within the file /rider/orders/controller.php?action=edit&actions=confirm, part of the Order Status Update component. An attacker can manipulate the 'ID' argument to perform SQL injection attacks. The vulnerability is remotely exploitable without requiring physical access to the target system. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-85187 and is tracked on VulDB and NVD. Organizations using this system should apply mitigations or patches immediately. The public disclosure raises the urgency for remediation given the potential for unauthorized database access.

Affected products

  • itsourcecode Online Medicine Delivery System 1.0

Related CVE's

  • CVE-2026-85187

Categories

  • Database & Storage
  • Web Technologies