CVE-2026-13578: itsourcecode Hospital Management System patientdetail.php sql injection
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Performing a manipulation of the argument editid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13578?
CVE-2026-13578 has a severity rating of low with a score of 2.1.
How do I fix CVE-2026-13578?
To fix CVE-2026-13578, ensure that proper input validation and parameterized queries are implemented in the patientdetail.php file to prevent SQL injection.
What type of vulnerability is CVE-2026-13578?
CVE-2026-13578 is classified as an SQL Injection vulnerability.
What software is affected by CVE-2026-13578?
The affected software for CVE-2026-13578 is the itsourcecode Hospital Management System version 1.0.
Can CVE-2026-13578 be exploited remotely?
Yes, CVE-2026-13578 can be exploited remotely by manipulating the editid argument in the patientdetail.php file.