← Terug naar overzicht

A SQL injection vulnerability has been identified in kishan0725 Hospital-Management-System version 1.0. The flaw exists in the /search.php file, where manipulation of the 'Contact' argument leads to SQL injection. The vulnerability can be exploited remotely without authentication. A public exploit has already been released, increasing the risk of active exploitation. The vendor was notified prior to disclosure but did not respond. This represents a critical risk for any organization running this software. The vulnerability is tracked as CVE-2026-82914 and is documented on NVD and VulDB.

Affected products

  • kishan0725 Hospital-Management-System 1.0

Related CVE's

  • CVE-2026-82914

Categories

  • Database & Storage
  • Web Technologies