CVE-2026-16244: itsourcecode Hospital Management System prescriptionorderreport.php sql injection
Published Jul 20, 2026
·Updated
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
1 affected component
itsourcecode Hospital Management System=1.0
Event History
Jul 20, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16244?
CVE-2026-16244 has a medium severity score of 6.3.
2
How does CVE-2026-16244 affect the itsourcecode Hospital Management System?
CVE-2026-16244 allows for SQL injection through the /prescriptionorderreport.php file by manipulating the delid argument.
3
Can CVE-2026-16244 be exploited remotely?
Yes, CVE-2026-16244 can be exploited remotely.
4
What type of vulnerability is CVE-2026-16244?
CVE-2026-16244 is classified as an SQL Injection vulnerability.
5
What action should be taken to mitigate CVE-2026-16244?
To mitigate CVE-2026-16244, sanitize user inputs for the delid argument in the /prescriptionorderreport.php file.