← Terug naar overzicht

A SQL injection vulnerability (CVE-2026-82612) has been identified in itsourcecode Online Medicine Delivery System version 1.0. The vulnerability exists in the loadResultList function within the /index.php?q=single-item file on the Product Detail Page. An attacker can manipulate the 'ID' argument to perform SQL injection attacks. The attack can be launched remotely without requiring physical access. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability affects the product's database interaction layer, potentially exposing sensitive medical and user data. No patch information is currently mentioned in the advisory.

Affected products

  • itsourcecode Online Medicine Delivery System 1.0

Related CVE's

  • CVE-2026-82612

Categories

  • Database & Storage
  • Web Technologies