Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
CVE-2026-16009
Description
A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
Affected products
1- Range: = 1.0
Patches
Vulnerability mechanics
References
6- github.com/ltranquility/submit_vuln/issues/8mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-16009mitrethird-party-advisory
- vuldb.com/submit/856775mitrethird-party-advisory
- itsourcecode.commitreproduct
- vuldb.com/vuln/379753mitrevdb-entrytechnical-description
- vuldb.com/vuln/379753/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.