← Terug naar overzicht

A SQL injection vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw exists in the Customer::find_phone function within the /passwordrecover.php file, part of the Password Recovery Interface component. An attacker can manipulate the 'phonenumber' argument to perform SQL injection attacks remotely. The vulnerability is exploitable over the network without requiring physical access. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-82615 and is tracked in VulDB. Affected users of the itsourcecode Online Medicine Delivery System 1.0 are advised to apply patches or mitigations promptly. The public disclosure of the exploit significantly elevates the urgency for remediation.

Affected products

  • itsourcecode Online Medicine Delivery System 1.0

Related CVE's

  • CVE-2026-82615

Categories

  • Database & Storage
  • Web Technologies