CVE-2026-16009: itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
Published Jul 17, 2026
·Updated
A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
1 affected component
itsourcecode Hospital Management System=1.0
Event History
Jul 17, 2026
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16009?
CVE-2026-16009 has a medium severity score of 6.3.
2
What type of vulnerability is CVE-2026-16009?
CVE-2026-16009 is a SQL Injection vulnerability.
3
How can CVE-2026-16009 be exploited?
CVE-2026-16009 can be exploited remotely by manipulating the 'delid' argument in the prescriptionorderdetail.php file.
4
What is affected by CVE-2026-16009?
CVE-2026-16009 affects version 1.0 of the itsourcecode Hospital Management System.
5
How do I fix CVE-2026-16009?
To fix CVE-2026-16009, validate and sanitize user inputs in the 'delid' parameter to prevent SQL injection.