← Terug naar overzicht

A SQL injection vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw exists in the Employee::employeeAuthentication function within the /rider/login.php file at the Login Interface component. Attackers can manipulate the emp_email argument to perform SQL injection attacks. The vulnerability is remotely exploitable without requiring physical access to the target system. A public exploit has already been released, increasing the risk of active exploitation. This type of vulnerability can allow attackers to bypass authentication and gain unauthorized access to the system. The affected product is a web-based medicine delivery management system. The issue has been documented in VulDB and the National Vulnerability Database. Organizations using this software should apply patches or mitigations immediately given the public availability of the exploit.

Affected products

  • itsourcecode Online Medicine Delivery System 1.0

Related CVE's

  • CVE-2026-82610

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies