← Terug naar overzicht

A critical vulnerability has been identified in itsourcecode Online Pharmacy System version 1.0. The flaw resides in the move_uploaded_file function within the all_users/register.php file, part of the User Registration component. By manipulating the 'photo' argument, an attacker can perform an unrestricted file upload, potentially allowing malicious files to be uploaded to the server. The attack can be launched remotely without requiring physical access. A public exploit has already been published, increasing the risk of active exploitation. This type of vulnerability can lead to remote code execution if a malicious script is uploaded and executed on the server. Organizations using this software should apply patches or mitigations immediately. The vulnerability has been catalogued in NVD, VulDB, and referenced in a GitHub issue report.

Affected products

  • itsourcecode Online Pharmacy System 1.0

Related CVE's

  • CVE-2026-78245

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities