CVE-2026-78112: itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection
Published Aug 23, 2026
·Updated
A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation of the argument delid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
1 affected component
itsourcecode Hospital Management System Project in PHP=1.0
Event History
Aug 23, 2026
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker with low privileges can exploit the SQL injection by manipulating the delid argument to /viewservicetype.php. No user interaction is required.
2
Is exploit code available?
Yes. The exploit has been published and may be used, increasing the likelihood of exploitation.
3
What security impact can this have?
The assigned vector indicates low impacts to confidentiality, integrity, and availability. Successful exploitation could affect all three security properties through the SQL injection flaw.