CVE-2026-14638: itsourcecode Hospital Management System patient.php sql injection
Published Jul 4, 2026
·Updated
A flaw has been found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /patient.php. This manipulation of the argument editid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
1 affected component
itsourcecode Hospital Management System=1.0
Event History
Jul 4, 2026
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Mar 3, 58477
Event
via NVD·01:06 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-14638?
The severity of CVE-2026-14638 is medium, with a score of 6.3.
2
How do I fix CVE-2026-14638?
To fix CVE-2026-14638, sanitize input in the patient.php file to prevent SQL injection.
3
What type of vulnerability is CVE-2026-14638?
CVE-2026-14638 is classified as an SQL injection vulnerability.
4
What is affected by CVE-2026-14638?
CVE-2026-14638 affects the itsourcecode Hospital Management System version 1.0.
5
Can CVE-2026-14638 be exploited remotely?
Yes, CVE-2026-14638 can be exploited remotely through the patient.php file.