What is CVE-2026-75088?
CVE-2026-75088 is a remote SQL injection vulnerability in itsourcecode Hospital Management System 1.0, affecting an unknown function in /viewbilling.php via the 'delid' argument. With a publicly disclosed exploit available, immediate mitigations such as input validation or restricting access to the affected file are strongly recommended until a vendor patch is released.
Azərbaycanca: CVE-2026-75088, itsourcecode Xəstəxana İdarəetmə Sistemi 1.0-da aşkar edilmiş uzaqdan SQL injection zəifliyidir. Bu zəiflik /viewbilling.php faylındakı 'delid' parametrini manipulyasiya etməklə istismar edilə bilər. İctimaiyyətə açıq istismar kodunun mövcudluğu riski artırdığı üçün sistem inzibatçıları dərhal giriş validasiyası tətbiq etməli və ya satıcıdan yamaq təmin edilənə qədər təsirlənən fayla girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: itsourcecode
FAQ2
Is there a publicly available exploit for CVE-2026-75088?
Yes, the risk of exploiting CVE-2026-75088 is increased due to the existence of a publicly disclosed exploit code.
What mitigation is recommended for CVE-2026-75088 until a vendor patch is released?
System administrators should immediately implement input validation or restrict access to the affected /viewbilling.php file until a vendor patch is provided.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.