CVE-2026-14773: itsourcecode Hospital Management System payment.php sql injection
A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /payment.php. The manipulation of the argument patientid results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14773?
The severity of CVE-2026-14773 is rated as medium with a score of 6.3.
How do I fix CVE-2026-14773?
To fix CVE-2026-14773, ensure that proper input validation and parameterized queries are implemented for the patientid argument in payment.php.
What type of vulnerability is CVE-2026-14773?
CVE-2026-14773 is an SQL Injection vulnerability affecting the itsourcecode Hospital Management System.
Can CVE-2026-14773 be exploited remotely?
Yes, CVE-2026-14773 can be exploited remotely due to the nature of the vulnerability.
Which version of itsourcecode is affected by CVE-2026-14773?
CVE-2026-14773 affects version 1.0 of the itsourcecode Hospital Management System.