CVE-2026-19068: itsourcecode Hospital Management System treatmentdetail.php sql injection
Published Aug 6, 2026
·Updated
A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /treatmentdetail.php. Executing a manipulation of the argument patientid can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
1 affected component
itsourcecode Hospital Management System=1.0
Event History
Aug 6, 2026
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19068?
The severity of CVE-2026-19068 is medium, with a score of 6.3.
2
What type of vulnerability is CVE-2026-19068?
CVE-2026-19068 is classified as an SQL Injection vulnerability.
3
How can I fix CVE-2026-19068?
To fix CVE-2026-19068, ensure proper validation and sanitization of the 'patientid' input in the /treatmentdetail.php file.
4
Is CVE-2026-19068 exploitable remotely?
Yes, CVE-2026-19068 can be exploited remotely.
5
What software is affected by CVE-2026-19068?
CVE-2026-19068 affects itsourcecode Hospital Management System version 1.0.