Impact
The vulnerability resides in the Customer::cusAuthentication function within /login.php of the Online Medicine Delivery System. By manipulating the U_USERNAME parameter, an attacker can inject arbitrary SQL, enabling unauthorized access or potentially sensitive data extraction. The affected code process user credentials without proper input validation or parameterization, leading directly to injection.
Affected Systems
The product impacted is itsourcecode Online Medicine Delivery System, version 1.0. Attackers can target the Customer Login Interface exposed by the component Customer Login Interface.
Risk and Exploitability
The CVSS score of 6.9 reflects elevated risk due to remote exploitation potential. EPSS data is not available, but public exploitation scripts are documented, indicating active usage. The vulnerability is not listed in CISA KEV, yet the exploit’s public availability suggests a non-negligible threat. Attack surface is reachable from any system with network access to the web interface, and no additional authentication is required to trigger the exploit.
OpenCVE Enrichment