CVE-2026-82611

A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

  • Published Aug 31, 2026
  • CVSS 5.5 medium
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-82611 at the National Vulnerability Database