Junglewise Threat Intelligence

CVE-2026-77025: itsourcecode Hospital Management System SQL injection in viewappointmentpending.php

CVE-2026-77025 · Severity: medium · CVSS 6.3 · Published 2026-08-20

Technologies: Itsourcecode Hospital Management System. Vendors: Itsourcecode.

Executive brief

itsourcecode Hospital Management System is a PHP-based web application for managing hospital operations including appointment scheduling. A SQL injection vulnerability in the appointment viewing functionality allows authenticated attackers to inject malicious SQL commands through the delid parameter, potentially exposing, modifying, or deleting sensitive patient data or gaining unauthorized system access.

Technical details

The vulnerability is a SQL injection flaw in the /viewappointmentpending.php file where the delid parameter is not properly sanitized before being incorporated into SQL queries. An attacker with valid login credentials can craft malicious SQL payloads (such as time-based blind SQL injection using SLEEP functions) to manipulate database queries. The attack is remotely exploitable via HTTP GET requests and requires valid authentication. A successful exploit allows an attacker to read, modify, or delete database records, potentially compromising patient data confidentiality, integrity, and system availability. The recommended fix is to implement prepared statements with parameter binding and enforce strict input validation.

Affected products

  • itsourcecode Hospital Management System 1.0

Timeline

  • 2026-07-05: disclosed
  • 2026-08-20: advisory

References

Related threats