What is CVE-2026-19972?
A SQL injection vulnerability was found in itsourcecode Hospital Management System 1.0, specifically in the /viewpatient.php file via manipulation of the 'delid' argument. This allows remote attackers to execute arbitrary SQL queries. Users are advised to apply input validation and update the affected component immediately.
Azərbaycanca: itsourcecode Xəstəxana İdarəetmə Sisteminin 1.0 versiyasında, /viewpatient.php faylındakı 'delid' parametrinin manipulyasiyası ilə SQL injection zəifliyi aşkar edilib. Bu, sistemə uzaqdan müdaxilə etməyə imkan yaradır. İstifadəçilərə dərhal kodu yeniləmək və giriş validasiyasını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: itsourcecode
FAQ2
Where is the CVE-2026-19972 vulnerability located in the itsourcecode Hospital Management System?
The vulnerability is found in the /viewpatient.php file via the 'delid' argument.
What can a remote attacker do by exploiting CVE-2026-19972?
A remote attacker can execute arbitrary SQL queries.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.