CVE-2026-82615

A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function Customer::find_phone of the file /passwordrecover.php of the component Password Recovery Interface. The manipulation of the argument phonenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 05:17

Updated : 2026-08-31 20:56


NVD link : CVE-2026-82615

Mitre link : CVE-2026-82615

CVE.ORG link : CVE-2026-82615


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')