CVE-2026-19767: medium-severity vulnerability in itsourcecode Hospital Management System
itsourcecode Hospital Management System viewdoctortimings.php sql injection
Published
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
itsourcecode · Hospital Management Systempublic PoCs found — 1
cve_referencegithub.com/funw1n/CVE/issues/1unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — itsourcecode Hospital Management System
In the same product, most dangerous first.
CVE-2026-13495MEDIUMitsourcecode Hospital Management System adminprofile.php sql injectionEPSS 0.3%CVE-2026-77025MEDIUMitsourcecode Hospital Management System viewappointmentpending.php sql injectionEPSS 0.3%CVE-2026-76991MEDIUMitsourcecode Hospital Management System viewappointmentapproved.php sql injectionEPSS 0.3%CVE-2026-75088MEDIUMitsourcecode Hospital Management System viewbilling.php sql injectionEPSS 0.3%CVE-2026-75087MEDIUMitsourcecode Hospital Management System viewdepartment.php sql injectionEPSS 0.3%CVE-2026-75086MEDIUMitsourcecode Hospital Management System viewroom.php sql injectionEPSS 0.3%