CVE-2026-13548: itsourcecode Hospital Management System doctortimings.php sql injection
Published Jun 29, 2026
·Updated
A vulnerability was identified in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /doctortimings.php. The manipulation of the argument editid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected Software
1 affected component
itsourcecode Hospital Management System=1.0
Event History
Jun 29, 2026
CVE Published
via MITRE·07:45 AM
Data Sourced
via MITRE·07:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-13548?
The severity of CVE-2026-13548 is medium with a score of 6.3.
2
How do I fix CVE-2026-13548?
To fix CVE-2026-13548, validate and sanitize the input for the 'editid' parameter in doctortimings.php to prevent SQL injection.
3
What type of vulnerability is CVE-2026-13548?
CVE-2026-13548 is classified as an SQL Injection vulnerability.
4
Can CVE-2026-13548 be exploited remotely?
Yes, CVE-2026-13548 allows for remote exploitation due to the nature of the SQL injection flaw.
5
What software is affected by CVE-2026-13548?
CVE-2026-13548 affects the itsourcecode Hospital Management System version 1.0.