Description
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2026-06-07: | Advisory disclosed |
| 2026-06-07: | VulDB entry created |
| 2026-06-07: | VulDB entry last update |
Credits
Aki123 (VulDB User)
References
vuldb.com/vuln/369132 (VDB-369132 | itsourcecode Hospital Management System billing.php cross site scripting)
vuldb.com/vuln/369132/cti (VDB-369132 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-11512 (CVE-2026-11512 | CVE Analysis and Report)
vuldb.com/submit/836161 (Submit #836161 | itsourcecode Hospital Management System V1.0 Cross Site Scripting)
github.com/ltranquility/vuln_submit/issues/13
itsourcecode.com/