← Terug naar overzicht

A SQL injection vulnerability has been identified in itsourcecode Online Clinic Management System version 1.0. The vulnerability exists in the file success/login.php within the Admin Login component. An attacker can manipulate the Username argument to perform SQL injection attacks. The vulnerability is remotely exploitable, meaning no local access is required. A public exploit has already been disclosed and may be actively used by attackers. This poses a significant risk to healthcare management systems running this software. The vulnerability has been catalogued as CVE-2026-78246 and tracked across multiple security databases including NVD and VulDB.

Affected products

  • itsourcecode Online Clinic Management System 1.0

Related CVE's

  • CVE-2026-78246

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies