What is CVE-2026-19364?
An SQL injection vulnerability was found in an unknown function of the /viewdoctorconsultancycharge.php file in itsourcecode Hospital Management System 1.0. This allows remote attackers to manipulate the database via the `delid` argument. Immediate input validation and system patching are required.
Azərbaycanca: itsourcecode Hospital Management System 1.0 proqramında /viewdoctorconsultancycharge.php faylındakı naməlum funksiyada SQL injection zəifliyi aşkar edilib. Bu, uzaqdan hücum edənə `delid` arqumenti vasitəsilə verilənlər bazasına müdaxilə etməyə imkan verir. Təcili olaraq daxil olan məlumatların yoxlanılması tətbiq edilməli və sistem yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: itsourcecode
FAQ2
Which software is affected by the CVE-2026-19364 vulnerability?
This vulnerability affects version 1.0 of the itsourcecode Hospital Management System.
How can an attacker manipulate the database using CVE-2026-19364?
An attacker can manipulate the database by performing SQL injection through the `delid` argument in the `/viewdoctorconsultancycharge.php` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.