Junglewise Threat Intelligence

CVE-2026-14731: itsourcecode Hospital Management System SQL injection in patientreport.php

CVE-2026-14731 · Severity: medium · CVSS 6.3 · Published 2026-07-05

Technologies: Itsourcecode Hospital Management System. Vendors: Itsourcecode.

Executive brief

A vulnerability exists in the itsourcecode Hospital Management System, a software platform used for managing patient records and hospital operations. An attacker with basic user credentials can exploit this flaw to gain unauthorized access to the underlying database. This could result in the exposure of sensitive patient information, data tampering, or disruption of hospital services.

Technical details

A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 within the '/patientreport.php' component. The root cause is the improper neutralization of special elements in the 'editid' GET parameter, which is used in SQL queries without sufficient sanitization or parameterization. An authenticated attacker can exploit this by sending a specially crafted GET request to manipulate database queries. Successful exploitation allows for unauthorized data retrieval, modification, or potential full database compromise. A public proof-of-concept (PoC) using error-based injection techniques has been disclosed.

Affected products

  • itsourcecode Hospital Management System 1.0

Timeline

  • 2026-06-04: disclosed: Vulnerability reported on GitHub repository
  • 2026-07-05: advisory: NVD publication date

References

Related threats