Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
2.1
CVE-2026-13542: itsourcecode Hospital Management System 1.0 Doctor Profile SQL Injection
CVE-2026-13542
Summary
A security issue in itsourcecode Hospital Management System 1.0 allows an attacker to inject malicious SQL code through the doctor's name field. This could allow unauthorized access to sensitive information. We recommend updating to the latest version of the software to fix this issue.
Original title
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the argument doctornam...
Original description
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
nvd CVSS2.0
6.5
nvd CVSS3.1
6.3
nvd CVSS4.0
2.1
Vulnerability type
CWE-74
Injection
CWE-89
SQL Injection
Published: 29 Jun 2026 · Updated: 1 Jul 2026 · First seen: 29 Jun 2026