A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList of the file /index.php?q=single-item of the component Product Detail Page. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
PUBLISHED5.2ApplicationCWE-89CWE-74x_freeware
itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injection
Problem type
Affected products
itsourcecode
Online Medicine Delivery System
1.0 - AFFECTED
References
VDB-397113 | itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injection
https://vuldb.com/vuln/397113
VDB-397113 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/397113/cti
CVE-2026-82612 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-82612
Submit #892910 | itsourcecode Online Medicine Delivery System v1.0 SQL Injection
https://vuldb.com/submit/892910
github.com
https://github.com/boyslikesports/202607_vul_dir/blob/main/C-03-SQLi-Single-Item-ID_en.md
itsourcecode.com
https://itsourcecode.com/
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-82612Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-82612",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-08-31T03:45:11.228Z",
"dateReserved": "2026-08-30T07:43:39.932Z",
"datePublished": "2026-08-31T03:45:11.228Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-08-31T03:45:11.228Z"
},
"title": "itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injection",
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList of the file /index.php?q=single-item of the component Product Detail Page. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used."
}
],
"affected": [
{
"vendor": "itsourcecode",
"product": "Online Medicine Delivery System",
"cpes": [
"cpe:2.3:a:itsourcecode:online_medicine_delivery_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Product Detail Page"
],
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "SQL Injection",
"cweId": "CWE-89",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Injection",
"cweId": "CWE-74",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/397113",
"name": "VDB-397113 | itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/397113/cti",
"name": "VDB-397113 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-82612",
"name": "CVE-2026-82612 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/892910",
"name": "Submit #892910 | itsourcecode Online Medicine Delivery System v1.0 SQL Injection",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/boyslikesports/202607_vul_dir/blob/main/C-03-SQLi-Single-Item-ID_en.md",
"tags": [
"exploit"
]
},
{
"url": "https://itsourcecode.com/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2026-08-30T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-08-30T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-08-30T09:49:37.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "Weining Xiao (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
}
}
}