← Terug naar overzicht

A SQL injection vulnerability has been identified in code-projects Hospital Information System version 1.0. The vulnerability exists in the viewReq function within the viewReq.php file, where manipulation of the 'ID' argument allows for SQL injection attacks. The attack can be executed remotely without requiring physical access to the target system. A public exploit is already available, increasing the risk of exploitation in the wild. The vulnerability affects the data integrity and confidentiality of the hospital information system's database. Given the sensitive nature of healthcare data and the public availability of the exploit, this represents a significant risk. The issue has been documented across multiple security databases including NVD, VulDB, and GitHub.

Affected products

  • code-projects Hospital Information System 1.0

Related CVE's

  • CVE-2026-85398

Categories

  • Critical Infrastructure
  • Database & Storage
  • Web Technologies