CVE-2026-85205: Itsourcecode Online Medicine Delivery System

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack may be initiated remotely.

Affected products

  • Itsourcecode Online Medicine Delivery System: version 1.0 only

Published 2026-09-03. Last modified 2026-09-15.