CVE-2026-14638: SQL Injection in itsourcecode Hospital Management System 1.0
A SQL injection vulnerability exists in itsourcecode Hospital Management System version 1.0 affecting the patient.php file. An authenticated attacker can manipulate the 'editid' parameter to execute arbitrary SQL queries, potentially reading, modifying, or deleting patient data. The vulnerability requires valid login credentials but no additional user interaction, making it exploitable by insiders or through credential compromise. Public exploit code has been released.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-74, CWE-89
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-04 / 2026-07-06
NVD description (verbatim)
A flaw has been found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /patient.php. This manipulation of the argument editid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-14638 is a SQL injection flaw (CWE-89) with improper neutralization of special elements (CWE-74) in itsourcecode Hospital Management System 1.0. The vulnerability exists in an unknown function within /patient.php where the 'editid' parameter is not properly sanitized before use in SQL queries. The attack vector is network-accessible, requires low complexity exploitation, and demands authenticated access. CVSS 3.1 score of 6.3 reflects confidentiality, integrity, and availability impact within the system's security boundary.
Business impact
Hospital Management Systems store sensitive protected health information (PHI). A successful SQL injection attack could enable unauthorized access to patient records, unauthorized modification of medical data (potentially affecting clinical decisions), or deletion of critical information. The presence of published exploit code elevates operational risk. For healthcare organizations, such compromises may trigger HIPAA breach notification obligations, regulatory fines, and patient trust erosion. Insider threats or external actors with stolen credentials pose immediate risk.
Affected systems
itsourcecode Hospital Management System version 1.0 is confirmed vulnerable. Organizations running this product should identify and inventory all instances, particularly those exposed to internal networks or the internet. The vendor information is limited; check the vendor's advisory for any affected minor versions, patched releases, or guidance on compatible versions.
Exploitability
The vulnerability is exploitable with moderate effort by an authenticated user. While remote network access is available, the authentication requirement limits exposure to users with valid credentials. The presence of publicly disclosed exploit code means proof-of-concept tools or attack patterns are available to threat actors, increasing practical exploit likelihood. Insider threats with legitimate access, credential compromise, or weak authentication mechanisms significantly elevate risk.
Remediation
Priority action: verify with itsourcecode whether patched versions exist for Hospital Management System 1.0 and deploy patches immediately. If no patch is available, consider isolating the system from untrusted networks, implementing strict access controls to /patient.php, and requiring multi-factor authentication for administrative accounts. Apply input validation and parameterized queries as defense-in-depth. For systems unable to patch, evaluate alternative products or schedule urgent upgrade planning.
Patch guidance
Contact itsourcecode directly or check their security advisories for available patches. Verify the patch version number in any advisory before deployment. Apply patches to all instances of Hospital Management System 1.0 in your environment. Test patches in a non-production environment first to ensure compatibility with your clinical workflows and integrations. If the vendor has not released a patch, implement compensating controls while awaiting a fix timeline.
Detection guidance
Monitor web server and database logs for SQL injection patterns in requests to /patient.php, particularly those containing SQL keywords (UNION, SELECT, OR, DROP) in the editid parameter. Look for unusual database activity from application service accounts (unexpected queries, error logs). Implement Web Application Firewall (WAF) rules to block common SQL injection syntax. Review authentication logs for unusual account access or privilege escalation. Database activity monitoring (DAM) solutions can alert on suspicious query execution.
Why prioritize this
Although CVSS 6.3 is moderate, healthcare context and published exploit code warrant elevated prioritization. Unauthorized access to medical records poses patient safety and regulatory compliance risks. The authentication requirement limits blast radius but does not eliminate urgency, especially if the system is internet-facing or accessible to a large internal user base. Organizations should treat this as a high-priority patch candidate.
Risk score, explained
CVSS 3.1 score of 6.3 (MEDIUM) reflects network accessibility and low attack complexity offset by the authentication requirement. The vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L) indicates modest impact on confidentiality, integrity, and availability within a single security boundary. In a healthcare environment, even 'low' impact to data confidentiality may carry outsized business and regulatory consequences, so context-driven risk assessment should supplement the technical score.
Frequently asked questions
Does this vulnerability affect Hospital Management System versions other than 1.0?
The published data confirms version 1.0 only. Contact itsourcecode or check their security advisories to determine if other versions are affected or if 1.0 has received patches.
What data is at risk if this vulnerability is exploited?
Any data accessible to the application's database connection is potentially at risk, including patient names, medical histories, diagnoses, treatment records, and contact information. The scope depends on database permissions and what data the /patient.php module manages.
Can this be exploited without valid credentials?
No. The CVSS vector specifies PR:L (requires Low privilege), meaning a valid user account is required. However, stolen credentials, insider threats, or weak authentication mechanisms can provide attackers with necessary access.
Is there a workaround if no patch is available?
Temporary mitigations include restricting network access to the system, enforcing strict firewall rules, implementing WAF rules to block SQL injection attempts, and monitoring database activity closely. These are not substitutes for patching but can reduce exposure while awaiting a fix.
This analysis is based on publicly available information as of the published date and may not reflect subsequent vendor patches or security updates. Organizations should verify all patch versions, compatibility, and deployment guidance directly with itsourcecode before applying fixes. This vulnerability analysis is for informational purposes and does not constitute professional security advice. Security teams should conduct independent risk assessments appropriate to their environment and consult vendor advisories for authoritative guidance. Source: NVD (public-domain), retrieved 2026-08-13. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10155MEDIUMSQL Injection in Bdtask Multi-Store Inventory Management System 1.0
- CVE-2026-10170MEDIUMSQL Injection in code-projects Visitor Management System 1.0
- CVE-2026-10171MEDIUMSQL Injection in code-projects Online Music Site 1.0 AdminUpdateAlbum.php
- CVE-2026-10176MEDIUMSQL Injection in Aider-AI Aider 0.86.3 Code Generation
- CVE-2026-10193MEDIUMSQL Injection in OFCMS ComnController – Authentication Required
- CVE-2026-10202MEDIUMOFCMS 1.1.3 SQL Injection in SystemDictController
- CVE-2026-10203MEDIUMSQL Injection in OFCMS 1.1.3 JSON Query Interface
- CVE-2026-10204MEDIUMSQL Injection in OFCMS 1.1.3 JSON Query Interface