A SQL injection vulnerability has been identified in code-projects Hospital Information System version 1.0. The vulnerability exists in the findBySearch function within the addReq.php file, where manipulation of the Search argument allows SQL injection attacks. The flaw can be exploited remotely without requiring physical access to the system. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability affects the integrity and confidentiality of the underlying database. Healthcare organizations using this software version should apply patches or mitigations immediately. The issue has been assigned CVE-2026-85397 and is tracked across multiple vulnerability databases.