CVE-2026-82615: itsourcecode Online Medicine Delivery System Password Recovery passwordrecover.php find_phone sql injection
A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function Customer::findphone of the file /passwordrecover.php of the component Password Recovery Interface. The manipulation of the argument phonenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of itsourcecode Online Medicine Delivery System 1.0 that expose the Password Recovery Interface and its passwordrecover.php endpoint are affected.
Does exploitation require authentication or user interaction?
No. The listed vector indicates network-accessible exploitation with no privileges or user interaction required.
What input is targeted by the attack?
The SQL injection is triggered by manipulation of the phonenumber argument passed to Customer::find_phone in /passwordrecover.php.
How urgent is mitigation?
Public exploit disclosure is reported, and remote exploitation is possible. Prioritize restricting access to the password recovery endpoint while remediation is investigated.