← Terug naar overzicht

A SQL injection vulnerability has been identified in itsourcecode Online Clinic Management System version 1.0. The vulnerability exists in the file success/login.php within the Admin Login component. An attacker can manipulate the Username argument to perform SQL injection attacks remotely. The exploit has been publicly disclosed and is available for use, making it an active threat. No authentication is required to exploit this vulnerability, increasing its severity. The issue affects an unspecified section of the login handling code. Successful exploitation could allow unauthorized access to the underlying database. Organizations using this system are advised to apply patches or mitigations promptly.

Affected products

  • itsourcecode Online Clinic Management System 1.0

Related CVE's

  • CVE-2026-78246

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies