These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-13495 is a SQL injection vulnerability in the itsourcecode Hospital Management System 1.0. The vulnerability is located in the /adminprofile.php file and is caused by improper input validation of the loginid argument. This allows an attacker to inject malicious SQL code, potentially leading to unauthorized access to sensitive data. The vulnerability has a CVSS score of 2 and a severity of LOW. Th [truncated]
A SQL injection vulnerability has been discovered in Itsourcecode Hospital Management System 1.0. The vulnerability exists in the /addpatient.php file and is caused by improper sanitization of user input in the admissiontme argument. This vulnerability allows remote attackers to inject malicious SQL code, potentially leading to unauthorized access or modification of sensitive data.
CVE-2026-11513 is a SQL injection vulnerability in itsourcecode Hospital Management System 1.0. The vulnerability affects an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in SQL injection. The attack can be launched remotely. The exploit is now public and may be used. The CVSS score is 2.1, and the severity is LOW.
A low-severity cross site scripting vulnerability has been detected in Itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
A SQL injection vulnerability has been detected in Itsourcecode Fees Management System 1.0. The vulnerability affects an unknown functionality of the file /receipt.php. Manipulation of the argument ef_id leads to SQL injection. The attack may be performed remotely. The exploit has been disclosed publicly and may be used.
A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
A SQL injection vulnerability was discovered in Itsourcecode Fees Management System 1.0. The vulnerability affects an unknown function of the file /manage_user.php and can be exploited remotely by manipulating the ID argument. The vulnerability has a CVSS score of 2.1 and is considered low-severity.
A SQL injection vulnerability was identified in Itsourcecode Fees Management System 1.0. The vulnerability affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to SQL injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
A SQL injection vulnerability exists in itsourcecode Content Management System 1.0, specifically in the /admin/edit_topic.php file via the topic_id parameter. The vulnerability allows remote attackers with low privileges to manipulate SQL queries. The CVSS 4.0 score of 2.1 (LOW) reflects limited impact scope, though the exploit is publicly available per source assessment. The vendor attribution is derived [truncated]
A SQL injection vulnerability exists in itsourcecode Online House Rental System 1.0, specifically within the /manage_payment.php file. The ID parameter is susceptible to manipulation, allowing remote attackers to inject arbitrary SQL commands. The vulnerability was disclosed publicly on 2026-06-01 and is rated MEDIUM severity with a CVSS score of 5.5. The exploit is publicly available, increasing the risk [truncated]
A SQL injection vulnerability exists in itsourcecode Online House Rental System 1.0, specifically in the /ajax.php?action=login endpoint where the Username parameter is improperly sanitized. The vulnerability allows remote attackers to manipulate SQL queries through crafted input. The issue was published on 2026-06-01 and carries a MEDIUM severity CVSS score of 5.5. Public exploit availability increases i [truncated]
A SQL injection vulnerability exists in itsourcecode Online Blood Bank Management System 1.0, specifically in the /admin/campsdetails.php file via the hospital parameter. The vulnerability allows remote attackers to manipulate SQL queries through crafted input to this parameter. The issue was published on 2026-06-01 with a CVSS 4.0 score of 5.5 (MEDIUM severity). The exploit has been publicly disclosed, i [truncated]
A SQL injection vulnerability exists in itsourcecode Online Blood Bank Management System 1.0, specifically within the /admin/viewrequest.php file. The vulnerability stems from improper sanitization of the 'ID' parameter, allowing remote attackers to manipulate SQL queries. The attack vector is network-based, requires no authentication, and has a low complexity. Public exploit availability increases risk, [truncated]
A SQL injection vulnerability exists in ITSourceCode Courier Management System 1.0, specifically in the `/parcel_list.php` file. The vulnerability allows remote attackers to manipulate the `s` parameter to inject malicious SQL commands. The CVSS 4.0 score of 2.1 (LOW severity) reflects limited privileges required and low impact on confidentiality, integrity, and availability. The exploit has been publicly [truncated]
A SQL injection vulnerability exists in itsourcecode Student Transcript Processing System 1.0, specifically in the /admin/modules/student/trans.php file. The vulnerability allows remote attackers to manipulate the studentId and cid parameters to inject malicious SQL commands. The CVSS 4.0 vector indicates network attack vector with low complexity, no privileges required, and low impacts on confidentiality [truncated]
A cross-site scripting (XSS) vulnerability exists in itsourcecode Electronic Judging System 1.0, specifically within the `/admin/judges.php` file. The `fname` parameter is susceptible to improper input sanitization, allowing remote attackers to inject malicious scripts. The vulnerability has been publicly disclosed with proof-of-concept availability, though exploitation requires user interaction. The CVSS [truncated]
A SQL injection vulnerability exists in itsourcecode Electronic Judging System 1.0, specifically in the /admin/edit_judge.php endpoint where the judge_id parameter is improperly sanitized. The vulnerability allows remote attackers to manipulate database queries through crafted input to this parameter. The issue was disclosed publicly on 2026-05-26 with exploit details available. The CVSS 4.0 vector indica [truncated]
A SQL injection vulnerability exists in the itsourcecode Electronic Judging System 1.0, specifically within the /intrams/admin/login.php endpoint. The Username parameter is susceptible to injection, enabling remote attackers to manipulate database queries. The vulnerability has been publicly disclosed with exploit availability confirmed, though no known ransomware campaign use has been identified. The CVS [truncated]
A SQL injection vulnerability has been identified in Itsourcecode Construction Management System 1.0. The vulnerability affects the /borrowed_tool_report.php file, where manipulation of the Home argument can lead to SQL injection. The attack can be initiated remotely. This issue has a CVSS score of 2.1, indicating a low severity. Security teams and administrators responsible for Itsourcecode Construction [truncated]
A SQL injection vulnerability was found in itsourcecode Construction Management System 1.0, specifically in the /borrowedtool.php file. The vulnerability allows remote attackers to inject malicious SQL code by manipulating the 'code' argument. This could lead to unauthorized access or modification of sensitive data. The exploit has been published and may be used, which increases the risk of attacks. Organ [truncated]
A SQL injection vulnerability was found in the itsourcecode Construction Management System 1.0. The vulnerability affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in SQL injection. It is possible to launch the attack remotely. This vulnerability has a high impact on data integrity and confidentiality. Security teams and [truncated]
A SQL injection vulnerability was found in itsourcecode Construction Management System 1.0. The vulnerability affects an unknown function of the file /borrowed_equip_report.php, specifically the 'Home' parameter. This vulnerability allows remote attackers to inject SQL. The exploit has been publicly disclosed. Administrators and users should be aware of this vulnerability and take necessary actions to mit [truncated]