A SQL injection vulnerability has been identified in code-projects Hospital Information System version 1.0. The vulnerability exists in the viewReq function within the viewReq.php file, where manipulation of the 'ID' argument allows SQL injection attacks. The flaw can be exploited remotely without requiring physical access to the target system. A public exploit is already available, increasing the risk of active exploitation. The vulnerability affects the integrity and confidentiality of the underlying database. Given the healthcare context, sensitive patient data may be at risk. The CVE identifier assigned is CVE-2026-85398, and it has been documented across multiple security databases including NVD and VulDB.