MEDIUMVulnerability

CVE-2026-85205

A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack may be initiated remotely.

Properties

severity
MEDIUM
score
6.3
cve_id
CVE-2026-85205
signal_observed_at
2026-09-15T21:20:01+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
published_at
2026-09-03T19:17:30.230
last_modified
2026-09-15T19:17:44.303

Related Entities (3)

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85205 — Ninja Signal Threat Intelligence | Ninja Signal