CVE-2026-85187 | itsourcecode Online Medicine Delivery System 1.0 Order Status Update controller.php?action=edit&actions=confirm Order::pupdate ID sql injection
A vulnerability, which was classified as critical, has been found in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm of the component Order Status Update. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2026-85187. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.VulDB Recent EntriesRead More