CVE-2026-19934: itsourcecode Hospital Management System vieworder.php sql injection
A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument delid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19934?
The severity of CVE-2026-19934 is rated as medium with a score of 6.3.
How do I fix CVE-2026-19934?
To fix CVE-2026-19934, users should validate and sanitize all input parameters in the vieworder.php file to prevent SQL injection.
What type of vulnerability is CVE-2026-19934?
CVE-2026-19934 is an SQL Injection vulnerability affecting the itsourcecode Hospital Management System.
Can CVE-2026-19934 be exploited remotely?
Yes, CVE-2026-19934 allows for remote exploitation of the SQL injection in vieworder.php.
Which file is affected by CVE-2026-19934?
CVE-2026-19934 affects the file vieworder.php in itsourcecode Hospital Management System.