CVE-2026-13532: itsourcecode Hospital Management System departmentDoctor.php sql injection
A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /departmentDoctor.php. This manipulation of the argument deptid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13532?
CVE-2026-13532 has a medium severity rating of 6.3.
What type of vulnerability is CVE-2026-13532?
CVE-2026-13532 is classified as an SQL Injection vulnerability.
How do I fix CVE-2026-13532?
To fix CVE-2026-13532, input validation and parameterized queries should be implemented in the /departmentDoctor.php file.
Can CVE-2026-13532 be exploited remotely?
Yes, CVE-2026-13532 can be exploited remotely due to the nature of the SQL injection vulnerability.
What software is affected by CVE-2026-13532?
CVE-2026-13532 affects the itsourcecode Hospital Management System version 1.0.