← Terug naar overzicht

A SQL injection vulnerability (CVE-2026-82613) has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw exists in the loadResultList function within the Product Search Interface component, accessible via /index.php?q=product. An attacker can manipulate the Search argument to perform SQL injection attacks remotely. The vulnerability is publicly disclosed and a working exploit is available, increasing the risk of active exploitation. No authentication appears to be required to trigger the vulnerability. The attack vector is network-based, making it accessible to remote threat actors. The severity is rated High due to the public exploit availability and remote exploitability. Organizations using this software should apply mitigations or patches immediately.

Affected products

  • itsourcecode Online Medicine Delivery System 1.0

Related CVE's

  • CVE-2026-82613

Categories

  • Database & Storage
  • Web Technologies