A critical security vulnerability has been identified in itsourcecode Online Medicine Delivery System version 1.0. The flaw resides in the doInsert function within /rider/orders/controller.php?action=add, part of the Order Management Controller component. By manipulating the 'image' argument, an attacker can perform an unrestricted file upload, potentially leading to remote code execution (RCE). The vulnerability is remotely exploitable without requiring physical access to the target system. A public exploit has already been released, increasing the risk of active exploitation in the wild. The affected system is a PHP-based web application used for managing medicine delivery orders. This issue is classified as high severity due to its public exploit availability and remote exploitability. Organizations using this software should apply patches or mitigations immediately.