CVE-2026-19767: itsourcecode Hospital Management System viewdoctortimings.php sql injection
A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19767?
The severity of CVE-2026-19767 is medium, with a base score of 6.3.
How do I fix CVE-2026-19767?
To fix CVE-2026-19767, validate and sanitize input for the delid parameter in viewdoctortimings.php to prevent SQL injection.
What type of attack is associated with CVE-2026-19767?
CVE-2026-19767 is associated with SQL injection attacks.
Can CVE-2026-19767 be exploited remotely?
Yes, CVE-2026-19767 can be exploited remotely due to its vulnerability in handling the delid parameter.
What software is affected by CVE-2026-19767?
The affected software is the itsourcecode Hospital Management System version 1.0.