GHSA-g8j6-f26h-5w34MediumCVSS 7.3
A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by...
🔗 CVE IDs covered (1)
📋 Description
A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-82611
- https://github.com/boyslikesports/202607_vul_dir/blob/main/C-02-SQLi-Customer-Auth-Bypass_en.md
- https://itsourcecode.com
- https://vuldb.com/cve/CVE-2026-82611
- https://vuldb.com/submit/892909
- https://vuldb.com/vuln/397112
- https://vuldb.com/vuln/397112/cti
- https://github.com/advisories/GHSA-g8j6-f26h-5w34