What is CVE-2026-16490?
A SQL injection vulnerability exists in the `/prescription.php` file of itsourcecode Hospital Management System 1.0, allowing remote attackers to manipulate the `editid` parameter. As the exploit is publicly available, immediate patching and input validation are required.
Azərbaycanca: itsourcecode Hospital Management System 1.0 proqramının `/prescription.php` faylında `editid` parametrini manipulyasiya etməklə uzaqdan SQL injection həyata keçirilə bilər. İstismar kodu ictimaiyyətə açıq olduğu üçün sistem dərhal ən son versiyaya yenilənməli və daxil olan məlumatlar filtrlənməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: itsourcecode
FAQ1
What critical vulnerability was discovered in itsourcecode Hospital Management System 1.0?
A remote SQL injection vulnerability exists in the `/prescription.php` file via the `editid` parameter. This flaw (CVE-2026-16490) allows unauthorized attackers to interfere with the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.