Impact
A tainted ID parameter in the Order::pupdate function of itsourcecode’s Online Medicine Delivery System allows attackers to inject arbitrary SQL statements. This vulnerability enables unauthenticated execution of SQL queries that can read, modify, or delete data stored in the application’s database, threatening the confidentiality and integrity of sensitive information such as user records, prescriptions, and financial transactions.
Affected Systems
Vulnerable only in itsourcecode’s Online Medicine Delivery System version 1.0, specifically the Order Status Update controller located in rider/orders/controller.php. The flaw affects any deployment that exposes the edit/confirm actions without a protective patch.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The EPSS score is not available, yielding an uncertain likelihood of exploitation; however, the vulnerability is remotely exploitable through standard web requests and has been publicly disclosed. No remote code execution capability is noted, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting no widespread exploitation at present.
OpenCVE Enrichment