What is CVE-2026-19347?
A SQL injection vulnerability was found in itsourcecode Hospital Management System 1.0, specifically in the /viewdoctor.php file via the 'delid' parameter. This remotely exploitable flaw could allow unauthorized access to sensitive database information. Users are advised to apply patches or seek mitigation immediately.
Azərbaycanca: itsourcecode Hospital Management System 1.0 proqramında /viewdoctor.php faylındakı 'delid' parametrində SQL injection zəifliyi aşkar edilib. Bu uzaqdan istismar oluna bilən təhlükə həssas verilənlər bazası məlumatlarına icazəsiz girişə səbəb ola bilər. İstifadəçilərə dərhal düzəliş tətbiq etmək və ya alternativ həll yolu axtarmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: itsourcecode
FAQ2
Where does the SQL injection vulnerability exist in itsourcecode Hospital Management System 1.0?
The vulnerability exists in the /viewdoctor.php file, specifically via the 'delid' parameter.
Is it possible to exploit this SQL injection vulnerability remotely?
Yes, this flaw is noted as a remotely exploitable vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.