在 itsourcecode 在线药品配送系统 1.0 版本中发现了一个漏洞。受影响的是文件 中某个未知函数。对参数 的操纵会导致跨站脚本攻击(XSS)。该攻击可远程发起。漏洞利用工具已公开可用,并可能已被利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| itsourcecode | Online Medicine Delivery System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| itsourcecode | Online Medicine Delivery System | 1.0 |
cpe:2.3:a:itsourcecode:online_medicine_delivery_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85208 | 7.3 HIGH | itsourcecode Online Medicine Delivery System Order Management Controller controller.php do |
| CVE-2026-85187 | 7.3 HIGH | itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sq |
| CVE-2026-85205 | 6.3 MEDIUM | itsourcecode Online Medicine Delivery System Wishlist controller.php addwishlist sql injec |
| CVE-2026-85186 | 6.3 MEDIUM | itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateim |
No comments yet