Junglewise Threat Intelligence

CVE-2026-85208: itsourcecode Online Medicine Delivery System unrestricted file upload in order management

CVE-2026-85208 · Severity: high · CVSS 7.3 · Published 2026-09-03

Technologies: Itsourcecode Online Medicine Delivery System. Vendors: Itsourcecode.

Executive brief

The Online Medicine Delivery System is a web application for managing medicine orders and deliveries. An attacker can upload malicious PHP files disguised as images to the server without authentication, gaining the ability to execute arbitrary commands and fully compromise the system. This allows theft of sensitive data like user credentials and database records, and can serve as a foothold for attacking internal networks.

Technical details

The vulnerability is an unrestricted file upload in the doInsert() function of /rider/orders/controller.php. The application uses getimagesize() to validate file type but fails to enforce file extension whitelisting or rename uploaded files. An attacker can bypass the image check by prepending a GIF89a header to PHP code, allowing the server to execute the file as a PHP script. The authentication check uses JavaScript redirect without terminating PHP execution, permitting unauthenticated requests to reach the upload handler. No authentication is required; a remote attacker can craft a multipart POST request to upload and execute arbitrary PHP code, achieving remote code execution and full server compromise.

Affected products

  • itsourcecode Online Medicine Delivery System 1.0

Timeline

  • 2026-09-03: disclosed
  • exploited: Exploit publicly released and may be used for attacks

References

Related threats