Executive brief
The kishan0725 Hospital Management System, a software suite used for managing patient records and clinical workflows, contains a security flaw in its patient editing module. An attacker could exploit this vulnerability to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive patient information or the modification of medical records. This could result in significant privacy breaches and operational disruptions for healthcare providers using the system.
Technical details
A SQL injection vulnerability exists in kishan0725 Hospital Management System 4.0 within the '/doctor/edit-patient.php' script. The application fails to properly sanitize the 'editid' GET parameter before using it in a database query. An attacker with network access to the doctor portal can provide malicious SQL commands through this parameter to bypass authentication, extract sensitive data from the database, or modify records. The vulnerability was identified via automated taint analysis (TaintRadar). No official patch has been confirmed at the time of reporting.
Affected products
- kishan0725 Hospital Management System 4.0
Timeline
- 2026-07-29: disclosed: Initial disclosure via NVD and TaintRadar repository.
- 2026-07-29: advisory