A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injection
Problem type
Affected products
itsourcecode
1.0 - AFFECTED
References
https://vuldb.com/vuln/397112
https://vuldb.com/vuln/397112/cti
https://vuldb.com/cve/CVE-2026-82611
https://vuldb.com/submit/892909
https://github.com/boyslikesports/202607_vul_dir/blob/main/C-02-SQLi-Customer-Auth-Bypass_en.md
https://itsourcecode.com/
GitHub Security Advisories
GHSA-g8j6-f26h-5w34
A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by...
https://github.com/advisories/GHSA-g8j6-f26h-5w34A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
https://nvd.nist.gov/vuln/detail/CVE-2026-82611
https://github.com/boyslikesports/202607_vul_dir/blob/main/C-02-SQLi-Customer-Auth-Bypass_en.md
https://itsourcecode.com
https://vuldb.com/cve/CVE-2026-82611
https://vuldb.com/submit/892909
https://vuldb.com/vuln/397112
https://vuldb.com/vuln/397112/cti
https://github.com/advisories/GHSA-g8j6-f26h-5w34
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-82611Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-82611",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-08-31T03:30:11.054Z",
"dateReserved": "2026-08-30T07:43:35.876Z",
"datePublished": "2026-08-31T03:30:11.054Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-08-31T03:30:11.054Z"
},
"title": "itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injection",
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks."
}
],
"affected": [
{
"vendor": "itsourcecode",
"product": "Online Medicine Delivery System",
"cpes": [
"cpe:2.3:a:itsourcecode:online_medicine_delivery_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Customer Login Interface"
],
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "SQL Injection",
"cweId": "CWE-89",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Injection",
"cweId": "CWE-74",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/397112",
"name": "VDB-397112 | itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/397112/cti",
"name": "VDB-397112 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-82611",
"name": "CVE-2026-82611 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/892909",
"name": "Submit #892909 | itsourcecode Online Medicine Delivery System v1.0 SQL Injection",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/boyslikesports/202607_vul_dir/blob/main/C-02-SQLi-Customer-Auth-Bypass_en.md",
"tags": [
"exploit"
]
},
{
"url": "https://itsourcecode.com/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2026-08-30T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-08-30T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-08-30T09:49:06.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "Weining Xiao (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
}
}
}