CVE-2026-19973: itsourcecode Hospital Management System viewpaymentreport.php sql injection
A vulnerability was found in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /viewpaymentreport.php. Performing a manipulation of the argument delid results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19973?
CVE-2026-19973 has a medium severity rating of 6.3.
How do I fix CVE-2026-19973?
To fix CVE-2026-19973, validate and sanitize input parameters in the /viewpaymentreport.php file to prevent SQL injection.
What impact does CVE-2026-19973 have on the Hospital Management System?
CVE-2026-19973 allows attackers to exploit SQL injection, potentially exposing sensitive data from the system.
Is CVE-2026-19973 exploitable remotely?
Yes, CVE-2026-19973 can be exploited remotely through the manipulation of input arguments.
Which version of the software is affected by CVE-2026-19973?
CVE-2026-19973 affects version 1.0 of the itsourcecode Hospital Management System.