CVE-2026-13496: itsourcecode Hospital Management System ajaxmedicine.php sql injection
A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argument medicineid results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13496?
The severity of CVE-2026-13496 is classified as medium with a score of 6.3.
How do I fix CVE-2026-13496?
To fix CVE-2026-13496, ensure that input validation and parameterized queries are implemented in the ajaxmedicine.php file.
What type of vulnerability is CVE-2026-13496?
CVE-2026-13496 is an SQL Injection vulnerability found in itsourcecode Hospital Management System.
Can CVE-2026-13496 be exploited remotely?
Yes, CVE-2026-13496 can be exploited remotely due to the nature of the vulnerability.
What is affected by CVE-2026-13496?
CVE-2026-13496 affects the ajaxmedicine.php file in itsourcecode Hospital Management System version 1.0.