A SQL injection vulnerability has been identified in code-projects Hospital Information System version 1.0. The flaw resides in the getSinglePresp function within the file includes/presp/PrespController.php, where manipulation of the 'ID' argument leads to SQL injection. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a hospital management web application, making the impact potentially critical due to sensitive patient data exposure. The vulnerability is tracked as CVE-2026-85399 and has been documented across multiple security databases including NVD and VulDB.