What is CVE-2026-20000?
This SQL injection vulnerability exists in the /viewprescriptionrecord.php file of itsourcecode Hospital Management System 1.0. It allows remote exploitation by manipulating the 'delid' argument. Immediate input validation and filtering must be implemented.
Azərbaycanca: Bu SQL injection zəifliyi itsourcecode Hospital Management System 1.0 versiyasının /viewprescriptionrecord.php faylında aşkarlanıb. `delid` arqumentinə müdaxilə etməklə uzaqdan istismar mümkündür. Təcili olaraq daxil olan məlumatların yoxlanılması və filtrlənməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: itsourcecode
FAQ2
In which file of itsourcecode Hospital Management System was CVE-2026-20000 discovered?
This SQL injection vulnerability was discovered in the /viewprescriptionrecord.php file of the application.
Which argument must be manipulated to exploit CVE-2026-20000?
The `delid` argument must be manipulated for remote exploitation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.