Impact
The flaw resides in the loadResultList function of the Online Medicine Delivery System 1.0, where the Category parameter is inserted directly into an SQL query. Manipulating this argument allows an attacker to embed arbitrary SQL code, which can be executed against the database. The vulnerability is reported as a SQL injection that can be triggered remotely by modifying a URL parameter, and publication of an exploit confirms that it can be used in real attacks.
Affected Systems
The vulnerability affects version 1.0 of the Online Medicine Delivery System from itsourcecode. No other versions or products appear to be impacted as of the current data.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity risk. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, but the presence of a publicly available exploit and the remote access nature of the attack point to a real chance of exploitation. The attacker needs only to craft a request to the vulnerable URL parameter to trigger the injection.
OpenCVE Enrichment