Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 03 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm of the component Order Status Update. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Title | itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injection | |
| First Time appeared |
Itsourcecode
Itsourcecode online Medicine Delivery System |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:itsourcecode:online_medicine_delivery_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Itsourcecode
Itsourcecode online Medicine Delivery System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-03T17:15:13.235Z
Reserved: 2026-09-03T11:53:58.738Z
Link: CVE-2026-85187
No data.
No data.
No data.
OpenCVE Enrichment
No data.