A vulnerability identified as critical has been detected in itsourcecode Hospital Management System 1.0 . This impacts an unknown function of the file /appointmentdetail.php of the component Appointment Handler . The manipulation of the argument editid leads to sql injection. This vulnerability is uniquely identified as CVE-2026-13530 . The attack is possible to be carried out remotely. Moreover, an exploit is present.