MEDIUM 5.5 NVD
CVE-2026-85187
A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the fil
A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm of the component Order Status Update. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
References
- https://github.com/boyslikesports/202607_vul_dir/blob/main/C-12-SQLi-Rider-Order-MultiPoin
- https://itsourcecode.com/
- https://vuldb.com/cve/CVE-2026-85187
- https://vuldb.com/submit/892987
- https://vuldb.com/vuln/398400
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-09-03 via NVD.
vulnfeed aggregates 7617 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.