Executive brief
A security vulnerability exists in the itsourcecode Hospital Management System, a software platform used to manage patient records and hospital operations. An attacker with basic user credentials can exploit this flaw to gain unauthorized access to the hospital's database. This could lead to the theft of sensitive patient information, tampering with medical records, or disruption of hospital services.
Technical details
A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 within the '/prescriptionorderdetail.php' file. The root cause is the failure to properly sanitize or validate the 'delid' parameter before it is used in a SQL query. An attacker with authenticated access (e.g., a patient login) can provide malicious SQL commands via a POST request to this parameter. Successful exploitation allows for unauthorized database access, data exfiltration, and potential modification of database records. A public proof-of-concept (PoC) demonstrating a time-based blind SQL injection (using SLEEP) has been disclosed. No official patch is currently documented; developers are advised to implement prepared statements and parameter binding.
Affected products
- itsourcecode Hospital Management System Project In PHP 1.0
Timeline
- 2026-06-12: disclosed: Vulnerability details and PoC shared on GitHub
- 2026-07-17: advisory: CVE-2026-16009 published by NVD/VulDB