CVE-2026-77025: itsourcecode Hospital Management System viewappointmentpending.php sql injection
Published Aug 20, 2026
·Updated
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
1 affected component
itsourcecode Hospital Management System=1.0
Event History
Aug 20, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs low-level privileges and can exploit the issue remotely. No user interaction is required.
2
Which input should be prioritized for review and mitigation?
Review the delid argument handled by /viewappointmentpending.php. The reported issue is SQL injection caused by manipulation of that argument.
3
Is public exploit information available?
Yes. The exploit has been publicly disclosed and could be used in attacks.