A vulnerability was found in itsourcecode Hospital Management System 1.0. It has been declared as critical. Impacted is an unknown function of the file /prescription.php. The manipulation of the argument editid results in sql injection.

This vulnerability is identified as CVE-2026-16490. The attack can be executed remotely. Additionally, an exploit exists.