A vulnerability described as critical has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection.

This vulnerability is uniquely identified as CVE-2026-19347. The attack can be launched remotely. Moreover, an exploit is present.