CVE-2026-14703: itsourcecode Hospital Management System patientorder.php sql injection
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /patientorder.php. Such manipulation of the argument editid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14703?
The severity of CVE-2026-14703 is classified as medium with a score of 6.3.
What type of vulnerability is CVE-2026-14703?
CVE-2026-14703 is an SQL injection vulnerability found in the itsourcecode Hospital Management System.
How do I fix CVE-2026-14703?
To fix CVE-2026-14703, validate and sanitize user input to prevent SQL injection attacks.
Which file is affected by CVE-2026-14703?
CVE-2026-14703 affects the file patientorder.php in the itsourcecode Hospital Management System.
Can CVE-2026-14703 be exploited remotely?
Yes, CVE-2026-14703 can be exploited remotely due to the nature of the SQL injection vulnerability.