VYPR

Online Medicine Delivery System

by Itsourcecode

CVEs (6)

  • CVE-2026-82615HigAug 31, 2026
    risk 0.47cvss 7.3epss

    A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function Customer::find_phone of the file /passwordrecover.php of the component Password Recovery Interface. The manipulation of the argument phonenumber leads to sql…

  • CVE-2026-82614HigAug 31, 2026
    risk 0.47cvss 7.3epss

    A flaw has been found in itsourcecode Online Medicine Delivery System 1.0. This vulnerability affects the function loadResultList of the file /index.php?q=product of the component Product Category Filter Interface. Executing a manipulation of the argument Category can lead to…

  • CVE-2026-82613HigAug 31, 2026
    risk 0.47cvss 7.3epss

    A vulnerability was detected in itsourcecode Online Medicine Delivery System 1.0. This affects the function loadResultList of the file /index.php?q=product of the component Product Search Interface. Performing a manipulation of the argument Search results in sql injection. The…

  • CVE-2026-82612HigAug 31, 2026
    risk 0.47cvss 7.3epss

    A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList of the file /index.php?q=single-item of the component Product Detail Page. Such manipulation of the argument ID leads to sql…

  • CVE-2026-82611HigAug 31, 2026
    risk 0.47cvss 7.3epss

    A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes…

  • CVE-2026-82610HigAug 31, 2026
    risk 0.47cvss 7.3epss

    A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. Affected is the function Employee::employeeAuthentication of the file /rider/login.php of the component Login Interface. The manipulation of the argument emp_email results in sql injection.…