Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm of the component Order Status Update. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Title | itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injection | |
| First Time appeared |
Itsourcecode
Itsourcecode online Medicine Delivery System |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:itsourcecode:online_medicine_delivery_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Itsourcecode
Itsourcecode online Medicine Delivery System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-03T17:15:13.235Z
Reserved: 2026-09-03T11:53:58.738Z
Link: CVE-2026-85187
No data.
Status : Deferred
Published: 2026-09-03T18:17:33.707
Modified: 2026-09-03T19:06:52.837
Link: CVE-2026-85187
No data.
OpenCVE Enrichment
Updated: 2026-09-03T18:45:07Z