What is CVE-2026-19894?
A SQL injection vulnerability was found in itsourcecode Hospital Management System 1.0 via the 'delid' parameter in /viewmedicine.php. This allows remote attackers to manipulate database queries. Immediate input validation or vendor patch is required.
Azərbaycanca: itsourcecode Hospital Management System 1.0 platformasında SQL injection zəifliyi aşkarlanıb. /viewmedicine.php faylındakı 'delid' parametrinin düzgün təmizlənməməsi uzaqdan müdaxiləyə imkan verir. Təcili olaraq giriş validasiyası tətbiq edilməli və ya rəsmi yamaq gözlənilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: itsourcecode
FAQ2
Which component of itsourcecode Hospital Management System is affected by CVE-2026-19894?
The vulnerability is found in the 'delid' parameter within /viewmedicine.php.
What measures are recommended to mitigate the risk of CVE-2026-19894?
Immediate input validation should be applied or a vendor patch must be awaited.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.