Junglewise Threat Intelligence

CVE-2026-13548: itsourcecode Hospital Management System SQL injection in doctortimings.php

CVE-2026-13548 · Severity: medium · CVSS 6.3 · Published 2026-06-29

Technologies: Itsourcecode Hospital Management System. Vendors: Itsourcecode.

Executive brief

A security vulnerability exists in the itsourcecode Hospital Management System, a software platform used for managing medical facility operations. An attacker with basic user access can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive patient records, unauthorized modification of medical data, or disruption of hospital services.

Technical details

A SQL injection vulnerability exists in the itsourcecode Hospital Management System 1.0 within the 'doctortimings.php' component. The root cause is the improper neutralization of special elements in the 'editid' GET parameter, which is used in SQL queries without sufficient validation or prepared statements. An attacker with low-privileged authentication can provide malicious payloads (such as error-based or time-based blind SQLi strings) to manipulate database queries. Successful exploitation allows for unauthorized data retrieval, modification, or potential full database compromise. A public exploit (PoC) using sqlmap has been disclosed.

Affected products

  • itsourcecode Hospital Management System 1.0

Timeline

  • 2026-05-29: disclosed: Vulnerability details and PoC shared on GitHub issue tracker
  • 2026-06-29: advisory: NVD and VulDB published the vulnerability details

References

Related threats