CVE-2026-19894: itsourcecode Hospital Management System viewmedicine.php sql injection
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewmedicine.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19894?
The severity of CVE-2026-19894 is classified as medium with a score of 6.3.
How do I fix CVE-2026-19894?
To fix CVE-2026-19894, sanitize and validate user inputs in the viewmedicine.php file to prevent SQL injection.
What impact does CVE-2026-19894 have on the itsourcecode Hospital Management System?
CVE-2026-19894 allows an attacker to perform SQL injection, potentially compromising the database and accessing sensitive information.
Can CVE-2026-19894 be exploited remotely?
Yes, CVE-2026-19894 can be exploited remotely by manipulating the 'delid' argument.
Which file is affected by CVE-2026-19894?
The affected file by CVE-2026-19894 is /viewmedicine.php in the itsourcecode Hospital Management System.