Impact
A flaw in the addwishlist function of itsourcecode Online Medicine Delivery System version 1.0 allows an attacker to manipulate the proid argument and inject arbitrary SQL commands. The injection can be triggered remotely via the web interface, potentially granting the attacker the ability to read, modify, or delete data stored in the database. The vulnerability is classified with a moderate CVSS score of 5.3 under CWE-74 (Improper Neutralization of Input During Database Query) and CWE-89 (SQL Injection).
Affected Systems
The affected software is itsourcecode Online Medicine Delivery System, version 1.0. No additional affected versions are specified beyond this release.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score is unavailable and the vulnerability is not listed in CISA KEV catalogues, suggesting limited publicly observed exploitation. Exploitation requires only remote access to the web interface and the ability to send a crafted proid value to the addwishlist endpoint. No special privileges or pre‑existing user access are required beyond reaching the vulnerable page.
OpenCVE Enrichment