CVE-2026-78246: itsourcecode Online Clinic Management System Admin Login login.php sql injection
A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit it without prior privileges or user interaction. The vulnerable input is the Username argument in the Admin Login component's success/login.php file.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used, increasing the likelihood of attempted exploitation.
What versions are known to be affected?
The provided information identifies itsourcecode Online Clinic Management System version 1.0 as affected. No other version information is provided.