CVE-2026-16334: itsourcecode Hospital Management System prescriptionorder.php sql injection
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16334?
CVE-2026-16334 has a medium severity rating of 6.3.
What exploit is associated with CVE-2026-16334?
CVE-2026-16334 is associated with a SQL injection vulnerability in the prescriptionorder.php file of the itsourcecode Hospital Management System.
How does CVE-2026-16334 affect itsourcecode Hospital Management System?
CVE-2026-16334 allows remote attackers to manipulate the editid parameter, leading to SQL injection.
How do I fix CVE-2026-16334?
To fix CVE-2026-16334, implement input validation and use prepared statements to protect against SQL injection.
Is there a known exploit for CVE-2026-16334?
Yes, there is a publicly available exploit for CVE-2026-16334.