← Back to overview

A SQL injection vulnerability was identified in code-projects Hospital Information System version 1.0. The vulnerability exists in the findBySearch function within the addReq.php file, where manipulation of the Search argument leads to SQL injection. The attack can be initiated remotely without requiring local access. A public exploit has been disclosed and is available for use, increasing the risk of exploitation. This vulnerability poses a significant risk to healthcare systems utilizing this software, potentially allowing attackers to access, manipulate, or exfiltrate sensitive patient and hospital data stored in the database.

Affected products

  • code-projects Hospital Information System 1.0

Related CVE's

  • CVE-2026-85397

Categories

  • Critical Infrastructure
  • Database & Storage
  • Web Technologies