Junglewise Threat Intelligence

CVE-2026-13579: itsourcecode Hospital Management System SQL injection in patientchangepassword.php

CVE-2026-13579 · Severity: medium · CVSS 6.3 · Published 2026-06-29

Technologies: Itsourcecode Hospital Management System. Vendors: Itsourcecode.

Executive brief

itsourcecode Hospital Management System is a web application used for managing medical facility operations. A security vulnerability in the password change feature allows logged-in users to execute unauthorized database commands. This could lead to the theft of sensitive patient data, unauthorized modification of medical records, or disruption of hospital services.

Technical details

A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 within the '/patientchangepassword.php' file. The root cause is the improper neutralization of special elements in the 'newpassword' POST parameter. An attacker with valid patient credentials can exploit this via a time-based blind SQL injection attack to manipulate backend database queries. Successful exploitation can lead to unauthorized database access, data leakage, and potential system control. A public proof-of-concept (PoC) using sqlmap has been disclosed. No official patch is currently documented, but remediation should involve implementing prepared statements and input validation.

Affected products

  • itsourcecode Hospital Management System 1.0

Timeline

  • 2026-05-31: disclosed: Initial vulnerability report on GitHub
  • 2026-06-29: advisory: NVD publication date

References

Related threats