CVE-2026-85205
A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack may be initiated remotely.
- Published Sep 3, 2026
- CVSS 5.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)