Junglewise Threat Intelligence

CVE-2026-13532: itsourcecode Hospital Management System SQL injection in departmentDoctor.php

CVE-2026-13532 · Severity: medium · CVSS 6.3 · Published 2026-06-29

Technologies: Itsourcecode Hospital Management System. Vendors: Itsourcecode.

Executive brief

A security vulnerability exists in the itsourcecode Hospital Management System, a software platform used for managing medical facility operations. An attacker with basic user credentials can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive patient information, unauthorized modification of medical records, or disruption of hospital services.

Technical details

A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 within the '/departmentDoctor.php' file. The root cause is the improper neutralization of the 'deptid' GET parameter, which is used in SQL queries without sufficient sanitization or parameterization. An authenticated attacker can exploit this remotely using various techniques, including boolean-based blind, error-based, time-based blind, and UNION-based SQL injection. Successful exploitation allows for unauthorized database access, data exfiltration, and potential system control. A public exploit (PoC) using sqlmap has been disclosed.

Affected products

  • itsourcecode Hospital Management System 1.0

Timeline

  • 2026-05-28: disclosed: Vulnerability details and PoC shared on GitHub
  • 2026-06-29: advisory: NVD/VulDB advisory published

References

Related threats