What is CVE-2026-19767?
A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 via the `delid` parameter in `viewdoctortimings.php`. This allows remote attackers to manipulate database queries. Proper input sanitization and the use of parameterized queries are recommended to prevent exploitation.
Azərbaycanca: itsourcecode Hospital Management System 1.0-da `viewdoctortimings.php` faylında `delid` parametrinin düzgün işlənməməsi SQL injection zəifliyinə səbəb olur. Bu, uzaqdan hücumçuya verilənlər bazasını manipulyasiya etməyə imkan verir. Təsirə məruz qalmamaq üçün daxil olan məlumatların təmizlənməsi və parametrləşdirilmiş sorğulardan istifadə edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: itsourcecode
FAQ2
In which product and file does CVE-2026-19767 exist?
This SQL injection vulnerability exists in the `viewdoctortimings.php` file of `itsourcecode Hospital Management System` version 1.0.
What measures are recommended to prevent the exploitation of CVE-2026-19767?
To prevent exploitation, proper input sanitization and the use of parameterized queries are recommended at the application level.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.