CVE-2026-19067: itsourcecode Hospital Management System treatment.php sql injection
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19067?
CVE-2026-19067 has a medium severity rating of 6.3.
How do I fix CVE-2026-19067?
To fix CVE-2026-19067, ensure that user inputs for the 'editid' parameter are properly sanitized and use prepared statements to prevent SQL injection.
What kind of vulnerability is CVE-2026-19067?
CVE-2026-19067 is an SQL injection vulnerability found in the itsourcecode Hospital Management System.
What could happen if CVE-2026-19067 is exploited?
If exploited, CVE-2026-19067 could allow an attacker to manipulate the database and access sensitive information.
Is remote exploitation possible with CVE-2026-19067?
Yes, CVE-2026-19067 is vulnerable to remote exploitation.