CVE-2026-13579: itsourcecode Hospital Management System patientchangepassword.php sql injection
Published Jun 29, 2026
·Updated
A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
1 affected component
itsourcecode Hospital Management System=1.0
Event History
Jun 29, 2026
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-13579?
The severity of CVE-2026-13579 is medium with a score of 6.3.
2
How do I fix CVE-2026-13579?
To fix CVE-2026-13579, sanitize and validate user input on the newpassword parameter to prevent SQL injection.
3
What systems are affected by CVE-2026-13579?
CVE-2026-13579 affects the itsourcecode Hospital Management System version 1.0.
4
What type of vulnerability is CVE-2026-13579?
CVE-2026-13579 is a SQL injection vulnerability.
5
Can CVE-2026-13579 be exploited remotely?
Yes, CVE-2026-13579 can be exploited remotely.