CVE-2026-14659: itsourcecode Hospital Management System patientappointment.php sql injection
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /patientappointment.php. Such manipulation of the argument patiente leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14659?
The severity of CVE-2026-14659 is classified as medium with a score of 6.3.
How does CVE-2026-14659 affect itsourcecode Hospital Management System?
CVE-2026-14659 allows for SQL injection through the /patientappointment.php file, affecting the handling of the 'patiente' parameter.
What systems are vulnerable to CVE-2026-14659?
CVE-2026-14659 affects the itsourcecode Hospital Management System version 1.0.
Can CVE-2026-14659 be exploited remotely?
Yes, CVE-2026-14659 can be exploited remotely, allowing attackers to manipulate SQL queries.
What is the potential impact of exploiting CVE-2026-14659?
Exploitation of CVE-2026-14659 can lead to unauthorized access to sensitive data in the database.