Impact
A reflected cross‑site scripting flaw exists in the Online Medicine Delivery System’s index.php page, triggered when an attacker manipulates the query string parameter "q=orderdetails". The application fails to validate or sanitize the supplied value before rendering it, allowing arbitrary HTML and script code to be injected into the response. According to the vulnerability description, this weakness corresponds to Input Validation Failure (CWE‑79) and Code Injection (CWE‑94). An attacker who successfully injects script can steal session cookies, hijack user sessions, deface the page, or redirect users to malicious sites.
Affected Systems
The affected product is itsourcecode Online Medicine Delivery System version 1.0. Because no other versions are specified, all installations running this release remain vulnerable until a vendor patch or mitigation is applied.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploit is publicly available, and an attacker can launch the attack remotely by crafting a malicious URL to the vulnerable endpoint.
OpenCVE Enrichment