CVE-2026-19767: fallo de gravedad media en itsourcecode Hospital Management System
itsourcecode Hospital Management System viewdoctortimings.php sql injection
Publicada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.3%
probabilidad de explotación
0.3%top 76% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
itsourcecode · Hospital Management SystemPoCs públicas encontradas — 1
cve_referencegithub.com/funw1n/CVE/issues/1no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — itsourcecode Hospital Management System
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-13495MEDIUMitsourcecode Hospital Management System adminprofile.php sql injectionEPSS 0.3%CVE-2026-77025MEDIUMitsourcecode Hospital Management System viewappointmentpending.php sql injectionEPSS 0.3%CVE-2026-76991MEDIUMitsourcecode Hospital Management System viewappointmentapproved.php sql injectionEPSS 0.3%CVE-2026-75088MEDIUMitsourcecode Hospital Management System viewbilling.php sql injectionEPSS 0.3%CVE-2026-75087MEDIUMitsourcecode Hospital Management System viewdepartment.php sql injectionEPSS 0.3%CVE-2026-75086MEDIUMitsourcecode Hospital Management System viewroom.php sql injectionEPSS 0.3%