Impact
A SQL injection flaw exists in the loadResultList function of index.php for the Product Search Interface in itsourcecode Online Medicine Delivery System. By manipulating the Search argument, an attacker can inject malicious SQL commands, potentially compromising database integrity and confidentiality. The flaw allows remote exploitation with no authentication required and the public exploit is available, raising the risk of data exposure or unauthorized data manipulation.
Affected Systems
The vulnerability affects the itsourcecode Online Medicine Delivery System version 1.0, specifically the component /index.php?q=product within the Product Search Interface.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium to high severity. EPSS information is unavailable, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, initiated via HTTP requests to the vulnerable endpoint. Given the public nature of the exploit and the lack of a requirement for local or privileged access, the risk remains significant until a patch is applied.
OpenCVE Enrichment