← Terug naar overzicht

A SQL injection vulnerability has been identified in code-projects Hospital Information System version 1.0. The flaw resides in the getSinglePresp function within the file includes/presp/PrespController.php. An attacker can manipulate the 'ID' argument to perform SQL injection attacks. The vulnerability is remotely exploitable, requiring no physical access to the target system. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a hospital management web application, making it potentially sensitive due to the nature of healthcare data it may handle. No authentication bypass details are specified, but the public availability of the exploit significantly raises the threat level.

Affected products

  • code-projects Hospital Information System 1.0

Related CVE's

  • CVE-2026-85399

Categories

  • Database & Storage
  • Enterprise Applications
  • Web Technologies