CVE-2026-19364: itsourcecode Hospital Management System viewdoctorconsultancycharge.php sql injection
A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19364?
CVE-2026-19364 has a medium severity rating of 6.3.
How does CVE-2026-19364 affect the itsourcecode Hospital Management System?
CVE-2026-19364 affects the itsourcecode Hospital Management System by allowing SQL injection through the /viewdoctorconsultancycharge.php file.
Can CVE-2026-19364 be exploited remotely?
Yes, CVE-2026-19364 can be exploited remotely, making it a significant security concern.
What components are involved in the CVE-2026-19364 vulnerability?
The involved component in CVE-2026-19364 is the unknown function handling the 'delid' argument in the /viewdoctorconsultancycharge.php file.
What steps should I take to mitigate CVE-2026-19364?
To mitigate CVE-2026-19364, ensure that your itsourcecode Hospital Management System is updated to the latest version with security patches.