CVE-2026-16131: itsourcecode Hospital Management System prescriptionrecord.php sql injection
Published Jul 18, 2026
·Updated
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
1 affected component
itsourcecode Hospital Management System=1.0
Event History
Jul 18, 2026
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16131?
The severity of CVE-2026-16131 is categorized as medium with a score of 6.3.
2
What type of vulnerability is CVE-2026-16131?
CVE-2026-16131 is classified as an SQL injection vulnerability.
3
How do I fix CVE-2026-16131?
To fix CVE-2026-16131, ensure proper validation and sanitization of user input in the prescriptionrecord.php file.
4
Can CVE-2026-16131 be exploited remotely?
Yes, CVE-2026-16131 can be exploited remotely due to its nature.
5
Which software is affected by CVE-2026-16131?
CVE-2026-16131 affects the itsourcecode Hospital Management System version 1.0.