Junglewise Threat Intelligence

CVE-2026-82610: itsourcecode Online Medicine Delivery System SQL injection in login

CVE-2026-82610 · Severity: high · CVSS 7.3 · Published 2026-08-31

Technologies: Itsourcecode Online Medicine Delivery System. Vendors: Itsourcecode.

Executive brief

Online Medicine Delivery System is a web-based platform for managing medicine delivery orders and employee access. A SQL injection vulnerability in the employee login page allows unauthenticated attackers to bypass authentication and gain full backend admin access, enabling them to access sensitive employee and customer data, modify orders, and manipulate business records.

Technical details

The vulnerability is a classic SQL injection flaw in the Employee::employeeAuthentication() method, located in /rider/login.php and include/employee.php. The emp_email parameter is directly concatenated into an SQL WHERE clause without parameterized queries or input sanitization. An attacker can inject SQL syntax (e.g., ' OR 1=1--) to make the authentication condition always true and bypass password verification, gaining immediate admin-level access without credentials. No authentication is required to exploit this vulnerability. The attack vector is network-based via POST request. A patch requires implementing parameterized queries and email format validation.

Affected products

  • itsourcecode Online Medicine Delivery System 1.0

Timeline

  • 2026-08-31: disclosed
  • exploited: Exploit publicly released

References

Related threats