SQL Injection Vulnerability in itsourcecode Online Medicine Delivery System
CVE-2026-85205
5.3MEDIUM
What is CVE-2026-85205?
A security issue identified in the itsourcecode Online Medicine Delivery System version 1.0 pertains to the 'addwishlist' function within the '/customer/controller.php?action=addwish' file. This vulnerability arises from improper handling of the 'proid' argument, allowing attackers to inject malicious SQL queries. The exploit can be triggered remotely, potentially compromising the application's database integrity and exposing sensitive information.
Affected Version(s)
Online Medicine Delivery System 1.0
