CVE-2026-85186 | itsourcecode Online Medicine Delivery System 1.0 Customer Controller controller.php?action=photos doupdateimage photo unrestricted upload

SecurityVulns

A vulnerability classified as critical was found in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of the component Customer Controller. Executing a manipulation of the argument photo can lead to unrestricted upload.

This vulnerability appears as CVE-2026-85186. The attack may be performed from remote. In addition, an exploit is available.VulDB Recent EntriesRead More