CVE-2026-19972: itsourcecode Hospital Management System viewpatient.php sql injection
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewpatient.php. Such manipulation of the argument delid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19972?
The severity of CVE-2026-19972 is classified as medium with a score of 6.3.
How do I fix CVE-2026-19972?
To fix CVE-2026-19972, ensure that proper input validation and parameterized queries are implemented to prevent SQL injection in the viewpatient.php file.
What systems are affected by CVE-2026-19972?
CVE-2026-19972 affects version 1.0 of the itsourcecode Hospital Management System.
What type of vulnerability is CVE-2026-19972?
CVE-2026-19972 is classified as an SQL injection vulnerability.
Can CVE-2026-19972 be exploited remotely?
Yes, CVE-2026-19972 can be exploited remotely by manipulating the delid argument in the viewpatient.php file.