CVE-2026-13497: itsourcecode Hospital Management System appointment.php sql injection
A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.php. This manipulation of the argument editid causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13497?
The severity of CVE-2026-13497 is classified as low with a score of 2.1.
What type of vulnerability is identified in CVE-2026-13497?
CVE-2026-13497 is identified as an SQL Injection vulnerability.
How can CVE-2026-13497 impact my system?
CVE-2026-13497 can allow an attacker to execute arbitrary SQL commands on the itsourcecode Hospital Management System remotely.
How do I fix CVE-2026-13497?
To fix CVE-2026-13497, validate and sanitize user input for the 'editid' parameter in the appointment.php file.
Is there a workaround for CVE-2026-13497?
One potential workaround for CVE-2026-13497 is to restrict access to the appointment.php file from untrusted networks.