Unrated severityNVD Advisory· Published Jun 28, 2026· Updated Jun 29, 2026
itsourcecode Hospital Management System ajaxmedicine.php sql injection
CVE-2026-13496
Description
A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argument medicineid results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected products
1- Range: = 1.0
Patches
Vulnerability mechanics
References
6- github.com/ltranquility/vuln_submit/issues/18mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-13496mitrethird-party-advisory
- vuldb.com/submit/838501mitrethird-party-advisory
- itsourcecode.commitreproduct
- vuldb.com/vuln/374491mitrevdb-entrytechnical-description
- vuldb.com/vuln/374491/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.