Unrated severityNVD Advisory· Published Jun 29, 2026· Updated Jun 30, 2026
itsourcecode Hospital Management System doctortimings.php sql injection
CVE-2026-13548
Description
A vulnerability was identified in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /doctortimings.php. The manipulation of the argument editid leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected products
1- Range: = 1.0
Patches
Vulnerability mechanics
References
6- github.com/ltranquility/submit/issues/19mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-13548mitrethird-party-advisory
- vuldb.com/submit/843063mitrethird-party-advisory
- itsourcecode.commitreproduct
- vuldb.com/vuln/374556mitrevdb-entrytechnical-description
- vuldb.com/vuln/374556/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.