CVE-2026-85205

Summary

A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack may be initiated remotely.

Affected Software

VendorProductVersion RangeStatus
itsourcecodeOnline Medicine Delivery System1.0affected

Weaknesses

  • CWE-89: SQL Injection
  • CWE-74: Injection

References