SQL Injection Weakness in itsourcecode Hospital Management System
CVE-2026-19068
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-19068?
A vulnerability exists in the itsourcecode Hospital Management System version 1.0, specifically in the treatmentdetail.php file. An attacker can exploit this weakness by manipulating the 'patientid' argument, which may lead to unauthorized access to the database. The attack can be executed remotely, making it a significant threat to data integrity. Publicly available exploit techniques further emphasize the need for immediate attention and mitigation strategies to protect sensitive healthcare information.
Affected Version(s)
Hospital Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
