CVE-2026-85208
Last modified
CVE-2026-85208 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of the component Order Management Controller.
Description
A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of the component Order Management Controller. Performing a manipulation of the argument image results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| itsourcecode | Online Medicine Delivery System | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-85208?
How severe is CVE-2026-85208?
How do I fix CVE-2026-85208?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-85187A security vulnerability has been detected in itsourcecode O…7.3
- CVE-2026-8519Integer overflow in ANGLE in Google Chrome on Windows prior …8.8
- CVE-2026-85199Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 con…8.8
- CVE-2026-8520Race in Payments in Google Chrome prior to 148.0.7778.168 al…8.3
- CVE-2026-85205A vulnerability was determined in itsourcecode Online Medici…6.3
- CVE-2026-85207A vulnerability was identified in itsourcecode Online Medici…3.5
- CVE-2026-8521Use after free in Tab Groups in Google Chrome prior to 148.0…7.5
- CVE-2026-85210Oppia's AdminRoleHandler GET endpoint in core/controllers/ad…4.3
- CVE-2026-85211Label Studio fails to apply organization filters when resolv…7.7
- CVE-2026-85212CRMEB contains an authentication bypass vulnerability in the…8.3
- CVE-2026-85213Kill Bill through 0.24.21 fails to enforce permission annota…7.6
- CVE-2026-85214vhr fails to validate user authorization in the PUT /hr/info…8.1
Are you affected by CVE-2026-85208?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
