Junglewise Threat Intelligence

CVE-2026-14773: itsourcecode Hospital Management System SQL injection in payment.php

CVE-2026-14773 · Severity: medium · CVSS 6.3 · Published 2026-07-05

Technologies: Itsourcecode Hospital Management System. Vendors: Itsourcecode.

Executive brief

A security vulnerability exists in the itsourcecode Hospital Management System, a software platform used for managing medical facility operations. An attacker with basic user credentials can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive patient information, data tampering, or disruption of hospital administrative services.

Technical details

A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 within the '/payment.php' component. The root cause is the improper sanitization of the 'patientid' GET parameter before it is used in a database query. A remote attacker with low-level authenticated access can provide a malicious payload (e.g., using error-based techniques like EXTRACTVALUE) to manipulate SQL queries. Successful exploitation allows for unauthorized database enumeration, data extraction, and potential modification of records. A public exploit (PoC) using sqlmap has been disclosed.

Affected products

  • itsourcecode Hospital Management System 1.0

Timeline

  • 2026-06-06: disclosed: Vulnerability details and PoC shared on GitHub
  • 2026-07-05: advisory: NVD/VulDB advisory published

References

Related threats