CVE-2026-85205: Itsourcecode Online Medicine Delivery System
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack may be initiated remotely.
Affected products
- Itsourcecode Online Medicine Delivery System: version 1.0 only
Published 2026-09-03. Last modified 2026-09-15.