Impact
A security flaw was discovered in the employeeAuthentication method of the login.php file in itsourcecode's Online Medicine Delivery System. By manipulating the emp_email parameter an attacker can inject arbitrary SQL statements, enabling authentication bypass and manipulation of the underlying database. This vulnerability is identified as CWE-74 and CWE-89.
Affected Systems
The affected product is the Online Medicine Delivery System 1.0 from itsourcecode. The fault lies in the login interface accessed through rider/login.php. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk. The exploit is publicly available, and the vulnerability can be triggered remotely via the web interface. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Attackers who succeed in exploiting this flaw could compromise the confidentiality and integrity of the system’s data by executing arbitrary SQL commands against the database.
OpenCVE Enrichment