Unrestricted Upload Vulnerability in itsourcecode Online Medicine Delivery System
CVE-2026-85186
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 3 September 2026
Badges
What is CVE-2026-85186?
A vulnerability exists in the itsourcecode Online Medicine Delivery System 1.0 that allows attackers to exploit the doupdateimage function in the Customer Controller component. By manipulating the photo argument in the controller.php file, unauthorized users may upload arbitrary files remotely, potentially leading to severe security consequences such as remote code execution. This vulnerability has been publicly disclosed and can be utilized by attackers to execute harmful payloads.
Affected Version(s)
Online Medicine Delivery System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
