---
id: CVE-2026-13520
title: A vulnerability was determined in itsourcecode Hospital Management System 1.0
summary: >-
  A vulnerability was determined in itsourcecode Hospital Management System 1.0.
  Affected is an unknown function of the file /appointmentapproval.php of the
  component Appointment Handler. This manipulation of the argument editid causes
  sql…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
published: '2026-06-29'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13520'
references:
  - url: 'https://github.com/ltranquility/cve_submit/issues/20'
    label: cna@vuldb.com
  - url: 'https://itsourcecode.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-13520'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/838994'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/374528'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/374528/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-06-29T13:42:12.317Z'
epss: 0.00333
epssPercentile: 0.23841
---

## Overview

A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
