Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
2.1
CVE-2026-16334: itsourcecode Hospital Management System: Malicious Prescription Orders
CVE-2026-16334
CVE-2026-16334
Summary
A security flaw in itsourcecode Hospital Management System allows hackers to inject malicious code into the system, potentially manipulating patient information and prescriptions. This could lead to unauthorized changes or theft of sensitive data. To protect your system, update to the latest version of itsourcecode Hospital Management System or consider alternative solutions.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| itsourcecode | hospital management system | 1.0 |
Original title
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid l...
Original description
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
mitre CVSS3.1
6.3
Vulnerability type
CWE-89
SQL Injection
CWE-74
Injection
- https://vuldb.com/vuln/380703 vdb-entry technical-description
- https://vuldb.com/vuln/380703/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-16334 third-party-advisory
- https://vuldb.com/submit/858648 third-party-advisory
- https://github.com/LiamJim/cve/issues/1 exploit issue-tracking
- https://itsourcecode.com/ product
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026