CVE-2026-13530: itsourcecode Hospital Management System Appointment appointmentdetail.php sql injection
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13530?
The severity of CVE-2026-13530 is classified as medium with a score of 6.3.
How do I fix CVE-2026-13530?
To fix CVE-2026-13530, validate and sanitize user inputs for the 'editid' parameter to prevent SQL injection.
What is the impact of CVE-2026-13530?
CVE-2026-13530 allows remote attackers to exploit SQL injection vulnerabilities in the appointmentdetail.php file.
Which component is affected by CVE-2026-13530?
CVE-2026-13530 affects the Appointment Handler component of the itsourcecode Hospital Management System.
What type of vulnerability is CVE-2026-13530?
CVE-2026-13530 is classified as an SQL Injection vulnerability.