A vulnerability classified as critical has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection.

The identification of this vulnerability is CVE-2026-19071. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.