PatchSiren

itsourcecode CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW itsourcecode CVE published 2026-08-09

CVE-2026-19347

A vulnerability was identified in itsourcecode Hospital Management System 1.0, affecting some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to SQL injection. The attack can be launched remotely. The exploit is publicly available. Security teams should review and verify the vulnerability, assess potential impact, and prioritize defensive actions accordingly. [truncated]

LOW itsourcecode CVE published 2026-08-06

CVE-2026-19071

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:54.883Z and has not been modified since then. The vulnerability is a SQL injection issue in Hospital Management System 1.0, specifically in the /viewappointment.php file. This type of vulnerability allows attackers to inject malicious SQL code, potentially leading to unauthorized access or [truncated]

LOW itsourcecode CVE published 2026-08-06

CVE-2026-19070

A vulnerability was detected in itsourcecode Hospital Management System 1.0, potentially allowing SQL injection via the /viewadmin.php file. The manipulation of the 'delid' argument is involved. The attack may be performed remotely. The exploit is now public and may be used. Limited details are available about the vulnerability's impact and exploitability. This CVE record was published on 2026-08-06T22:16 [truncated]

LOW itsourcecode CVE published 2026-08-06

CVE-2026-19068

A weakness has been identified in itsourcecode Hospital Management System 1.0, specifically in an unknown function of the file /treatmentdetail.php. This vulnerability allows for remote SQL injection via manipulation of the patientid argument. The CVE record was published on 2026-08-06T22:16:54.333Z and has not been modified since then. Security teams should review the vulnerability's existence and scope, [truncated]

LOW itsourcecode CVE published 2026-08-06

CVE-2026-19067

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:54.110Z and has not been modified since then. The vulnerability exists in the /treatment.php file of Itsourcecode Hospital Management System 1.0 due to improper sanitization of user input in the editid argument, leading to SQL injection. This allows remote attackers to inject malicious SQL [truncated]

LOW itsourcecode CVE published 2026-08-06

CVE-2026-19020

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:31.053Z and has not been modified since then. A SQL injection vulnerability exists in the /servicetype.php file of itsourcecode Hospital Management System 1.0. The vulnerability is triggered by manipulating the 'editid' argument. Remote exploitation is possible. The affected product is Hosp [truncated]

LOW itsourcecode CVE published 2026-07-22

CVE-2026-16490

A SQL injection vulnerability has been discovered in itsourcecode Hospital Management System 1.0, specifically in the /prescription.php file. This vulnerability is caused by improper input validation of the editid argument, allowing attackers to execute arbitrary SQL code. The potential impact includes data breaches or system compromise. Administrators and users should be aware of this vulnerability and t [truncated]

LOW itsourcecode CVE published 2026-07-21

CVE-2026-16334

A SQL injection vulnerability was identified in itsourcecode Hospital Management System 1.0. The vulnerability affects unknown code of the file /prescriptionorder.php. Manipulation of the argument editid leads to SQL injection. The attack can be launched remotely. The exploit is publicly available and might be used. This vulnerability has a CVSS score of 2.1 and a severity of LOW. Security teams and admin [truncated]

LOW itsourcecode CVE published 2026-07-20

CVE-2026-16244

A security vulnerability has been detected in Itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. Such manipulation of the argument delid leads to SQL injection. The attack may be launched remotely. This vulnerability affects Itsourcecode Hospital Management System 1.0, and users of this system should be aware of [truncated]

LOW itsourcecode CVE published 2026-07-18

CVE-2026-16131

A SQL injection vulnerability has been identified in Itsourcecode Hospital Management System 1.0. The vulnerability affects an unknown function of the file /prescriptionrecord.php and can be exploited remotely by manipulating the argument delid. This vulnerability has a CVSS score of 2.1, indicating a low severity. The vulnerability is caused by improper input validation in the /prescriptionrecord.php fil [truncated]

LOW itsourcecode CVE published 2026-07-17

CVE-2026-16009

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability has a CVSS score of 2.1 and a CVSS severity of LOW. Defenders of itsourcecode Hospital Manage [truncated]

LOW itsourcecode CVE published 2026-07-14

CVE-2026-15672

A SQL injection vulnerability was found in Itsourcecode Electronic Judging System 1.0. The issue is located in the /intrams/admin/add_judges.php file, where user input is not properly validated, allowing for SQL injection attacks. The vulnerability has been publicly disclosed and may be utilized. This issue affects administrators and users of the system, who should be aware of the vulnerability and take n [truncated]

LOW itsourcecode CVE published 2026-07-13

CVE-2026-15536

CVE-2026-15536 is a SQL injection vulnerability in Hospital Management System 1.0. The vulnerability affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid leads to SQL injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This vulnerability has a CVSS score of 2.1 and a severity of LOW. Security teams a [truncated]

LOW itsourcecode CVE published 2026-07-04

CVE-2026-14638

CVE-2026-14638 is a SQL injection vulnerability in itsourcecode Hospital Management System 1.0. The vulnerability affects an unknown function of the file /patient.php. This manipulation of the argument editid causes SQL injection. The attack may be initiated remotely. The exploit has been published and may be used. The CVSS score for this vulnerability is 2.1, indicating a low severity. The vulnerability [truncated]

LOW itsourcecode CVE published 2026-07-04

CVE-2026-14619

CVE-2026-14619 is a SQL injection vulnerability in the itsourcecode Hospital Management System 1.0. The vulnerability affects an unknown functionality of the /medicine.php file. An attacker can exploit this vulnerability by manipulating the editid argument, allowing for remote exploitation. The exploit has been published and may be used. The CVSS score for this vulnerability is 2.1, indicating a low severity.

MEDIUM itsourcecode CVE published 2026-06-29

CVE-2026-13555

CVE-2026-13555 is a SQL injection vulnerability in itsourcecode Online Hotel Management System 1.0. The vulnerability affects the /admin/mod_users/controller.php?action=add file. The manipulation of the Name argument results in SQL injection. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM.

LOW itsourcecode CVE published 2026-06-29

CVE-2026-13554

CVE-2026-13554 is a cross site scripting vulnerability found in itsourcecode Online Hotel Management System 1.0. The vulnerability affects an unknown functionality of the file /admin/mod_amenities/controller.php?action=add, specifically in the POST Request Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to t [truncated]

MEDIUM itsourcecode CVE published 2026-06-29

CVE-2026-13553

A medium-severity vulnerability, CVE-2026-13553, has been identified in itsourcecode Online Hotel Management System 1.0. The flaw, located in the /admin/mod_amenities/controller.php?action=add file, permits unrestricted file uploads when manipulating the 'image' argument. This vulnerability can be exploited remotely. The issue has been made public, and an exploit may be available. Organizations using the [truncated]

MEDIUM itsourcecode CVE published 2026-06-29

CVE-2026-13552

CVE-2026-13552 is a SQL injection vulnerability in itsourcecode Online Hotel Management System 1.0. The vulnerability is located in the /admin/mod_amenities/controller.php?action=edit file and can be exploited remotely. The exploit is now public and may be used. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The vendor is Unknown Vendor and the product is itsourcecode Online Hotel Man [truncated]

MEDIUM itsourcecode CVE published 2026-06-29

CVE-2026-13551

A SQL injection vulnerability was detected in itsourcecode Baptism Information Management System 1.0. The vulnerability affects an unknown function of the file /editBaptism.php. Manipulation of the argument ID leads to SQL injection. The attack may be performed remotely. The exploit has been disclosed publicly and may be used. Limited information is available about the vendor and product, and the CVE reco [truncated]

MEDIUM itsourcecode CVE published 2026-06-29

CVE-2026-13550

A SQL injection vulnerability has been identified in itsourcecode Baptism Information Management System 1.0. The vulnerability is located in the /delbaptism.php file and is caused by improper handling of the ID argument. This allows remote attackers to inject malicious SQL code. The exploit for this vulnerability has been made publicly available and could potentially be used for attacks. The CVSS score fo [truncated]

LOW itsourcecode CVE published 2026-06-29

CVE-2026-13531

CVE-2026-13531 is a SQL injection vulnerability in Itsourcecode Hospital Management System 1.0. The vulnerability affects an unknown function of the file /department.php. The manipulation of the argument editid results in SQL injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This vulnerability has a CVSS score of 2.1 and a severity of LOW.

LOW itsourcecode CVE published 2026-06-29

CVE-2026-13530

CVE-2026-13530 is a SQL injection vulnerability in the itsourcecode Hospital Management System 1.0. This vulnerability affects an unknown function of the /appointmentdetail.php file within the Appointment Handler component. The manipulation of the editid argument leads to SQL injection. The attack can be carried out remotely. The exploit is publicly available and may be used. The CVSS score for this vulne [truncated]

LOW itsourcecode CVE published 2026-06-29

CVE-2026-13520

CVE-2026-13520 is a SQL injection vulnerability in Itsourcecode Hospital Management System 1.0. The vulnerability affects an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes SQL injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. As of now, no pa [truncated]

LOW itsourcecode CVE published 2026-06-28

CVE-2026-13497

CVE-2026-13497 is a SQL injection vulnerability in itsourcecode Hospital Management System 1.0. The vulnerability is located in the /appointment.php file and is caused by the manipulation of the editid argument. This vulnerability allows remote attackers to inject malicious SQL code. The exploit has been publicly disclosed and may be utilized. The CVSS score for this vulnerability is 2.1, indicating a low [truncated]

LOW itsourcecode CVE published 2026-06-28

CVE-2026-13496

CVE-2026-13496 is a SQL injection vulnerability in the Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argument medicineid results in SQL injection. This vulnerability can be exploited remotely. The exploit has been made public and could be used. The CVSS score for this vulnerability is 2.1, indicating a low severity.

LOW itsourcecode CVE published 2026-06-28

CVE-2026-13495

CVE-2026-13495 is a SQL injection vulnerability in the itsourcecode Hospital Management System 1.0. The vulnerability is located in the /adminprofile.php file and is caused by improper input validation of the loginid argument. This allows an attacker to inject malicious SQL code, potentially leading to unauthorized access to sensitive data. The vulnerability has a CVSS score of 2 and a severity of LOW. Th [truncated]

LOW itsourcecode CVE published 2026-06-08

CVE-2026-11514

A SQL injection vulnerability has been discovered in Itsourcecode Hospital Management System 1.0. The vulnerability exists in the /addpatient.php file and is caused by improper sanitization of user input in the admissiontme argument. This vulnerability allows remote attackers to inject malicious SQL code, potentially leading to unauthorized access or modification of sensitive data.

LOW itsourcecode CVE published 2026-06-08

CVE-2026-11513

CVE-2026-11513 is a SQL injection vulnerability in itsourcecode Hospital Management System 1.0. The vulnerability affects an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in SQL injection. The attack can be launched remotely. The exploit is now public and may be used. The CVSS score is 2.1, and the severity is LOW.

LOW itsourcecode CVE published 2026-06-08

CVE-2026-11512

A low-severity cross site scripting vulnerability has been detected in Itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

LOW itsourcecode CVE published 2026-06-04

CVE-2026-10811

A SQL injection vulnerability has been detected in Itsourcecode Fees Management System 1.0. The vulnerability affects an unknown functionality of the file /receipt.php. Manipulation of the argument ef_id leads to SQL injection. The attack may be performed remotely. The exploit has been disclosed publicly and may be used.

LOW itsourcecode CVE published 2026-06-04

CVE-2026-10810

A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

LOW itsourcecode CVE published 2026-06-04

CVE-2026-10809

A SQL injection vulnerability was discovered in Itsourcecode Fees Management System 1.0. The vulnerability affects an unknown function of the file /manage_user.php and can be exploited remotely by manipulating the ID argument. The vulnerability has a CVSS score of 2.1 and is considered low-severity.

LOW itsourcecode CVE published 2026-06-04

CVE-2026-10808

A SQL injection vulnerability was identified in Itsourcecode Fees Management System 1.0. The vulnerability affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to SQL injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

LOW itsourcecode CVE published 2026-06-01

CVE-2026-10265

A SQL injection vulnerability exists in itsourcecode Content Management System 1.0, specifically in the /admin/edit_topic.php file via the topic_id parameter. The vulnerability allows remote attackers with low privileges to manipulate SQL queries. The CVSS 4.0 score of 2.1 (LOW) reflects limited impact scope, though the exploit is publicly available per source assessment. The vendor attribution is derived [truncated]

MEDIUM itsourcecode CVE published 2026-06-01

CVE-2026-10253

A SQL injection vulnerability exists in itsourcecode Online House Rental System 1.0, specifically within the /manage_payment.php file. The ID parameter is susceptible to manipulation, allowing remote attackers to inject arbitrary SQL commands. The vulnerability was disclosed publicly on 2026-06-01 and is rated MEDIUM severity with a CVSS score of 5.5. The exploit is publicly available, increasing the risk [truncated]

MEDIUM itsourcecode CVE published 2026-06-01

CVE-2026-10251

A SQL injection vulnerability exists in itsourcecode Online House Rental System 1.0, specifically in the /ajax.php?action=login endpoint where the Username parameter is improperly sanitized. The vulnerability allows remote attackers to manipulate SQL queries through crafted input. The issue was published on 2026-06-01 and carries a MEDIUM severity CVSS score of 5.5. Public exploit availability increases i [truncated]

MEDIUM itsourcecode CVE published 2026-06-01

CVE-2026-10250

A SQL injection vulnerability exists in itsourcecode Online Blood Bank Management System 1.0, specifically in the /admin/campsdetails.php file via the hospital parameter. The vulnerability allows remote attackers to manipulate SQL queries through crafted input to this parameter. The issue was published on 2026-06-01 with a CVSS 4.0 score of 5.5 (MEDIUM severity). The exploit has been publicly disclosed, i [truncated]

MEDIUM itsourcecode CVE published 2026-06-01

CVE-2026-10249

A SQL injection vulnerability exists in itsourcecode Online Blood Bank Management System 1.0, specifically within the /admin/viewrequest.php file. The vulnerability stems from improper sanitization of the 'ID' parameter, allowing remote attackers to manipulate SQL queries. The attack vector is network-based, requires no authentication, and has a low complexity. Public exploit availability increases risk, [truncated]

LOW itsourcecode CVE published 2026-05-27

CVE-2026-9607

A SQL injection vulnerability exists in ITSourceCode Courier Management System 1.0, specifically in the `/parcel_list.php` file. The vulnerability allows remote attackers to manipulate the `s` parameter to inject malicious SQL commands. The CVSS 4.0 score of 2.1 (LOW severity) reflects limited privileges required and low impact on confidentiality, integrity, and availability. The exploit has been publicly [truncated]

MEDIUM itsourcecode CVE published 2026-05-26

CVE-2026-9574

A SQL injection vulnerability exists in itsourcecode Student Transcript Processing System 1.0, specifically in the /admin/modules/student/trans.php file. The vulnerability allows remote attackers to manipulate the studentId and cid parameters to inject malicious SQL commands. The CVSS 4.0 vector indicates network attack vector with low complexity, no privileges required, and low impacts on confidentiality [truncated]

LOW itsourcecode CVE published 2026-05-26

CVE-2026-9527

A cross-site scripting (XSS) vulnerability exists in itsourcecode Electronic Judging System 1.0, specifically within the `/admin/judges.php` file. The `fname` parameter is susceptible to improper input sanitization, allowing remote attackers to inject malicious scripts. The vulnerability has been publicly disclosed with proof-of-concept availability, though exploitation requires user interaction. The CVSS [truncated]

MEDIUM itsourcecode CVE published 2026-05-26

CVE-2026-9525

A SQL injection vulnerability exists in itsourcecode Electronic Judging System 1.0, specifically in the /admin/edit_judge.php endpoint where the judge_id parameter is improperly sanitized. The vulnerability allows remote attackers to manipulate database queries through crafted input to this parameter. The issue was disclosed publicly on 2026-05-26 with exploit details available. The CVSS 4.0 vector indica [truncated]

MEDIUM itsourcecode CVE published 2026-05-24

CVE-2026-9383

A SQL injection vulnerability exists in the itsourcecode Electronic Judging System 1.0, specifically within the /intrams/admin/login.php endpoint. The Username parameter is susceptible to injection, enabling remote attackers to manipulate database queries. The vulnerability has been publicly disclosed with exploit availability confirmed, though no known ransomware campaign use has been identified. The CVS [truncated]

LOW itsourcecode CVE published 2026-04-09

CVE-2026-5823

A SQL injection vulnerability has been identified in Itsourcecode Construction Management System 1.0. The vulnerability affects the /borrowed_tool_report.php file, where manipulation of the Home argument can lead to SQL injection. The attack can be initiated remotely. This issue has a CVSS score of 2.1, indicating a low severity. Security teams and administrators responsible for Itsourcecode Construction [truncated]

LOW itsourcecode CVE published 2026-04-07

CVE-2026-5719

A SQL injection vulnerability was found in itsourcecode Construction Management System 1.0, specifically in the /borrowedtool.php file. The vulnerability allows remote attackers to inject malicious SQL code by manipulating the 'code' argument. This could lead to unauthorized access or modification of sensitive data. The exploit has been published and may be used, which increases the risk of attacks. Organ [truncated]

LOW itsourcecode CVE published 2026-04-06

CVE-2026-5675

A SQL injection vulnerability was found in the itsourcecode Construction Management System 1.0. The vulnerability affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in SQL injection. It is possible to launch the attack remotely. This vulnerability has a high impact on data integrity and confidentiality. Security teams and [truncated]

LOW itsourcecode CVE published 2026-04-06

CVE-2026-5620

A SQL injection vulnerability was found in itsourcecode Construction Management System 1.0. The vulnerability affects an unknown function of the file /borrowed_equip_report.php, specifically the 'Home' parameter. This vulnerability allows remote attackers to inject SQL. The exploit has been publicly disclosed. Administrators and users should be aware of this vulnerability and take necessary actions to mit [truncated]