Junglewise Threat Intelligence

CVE-2026-10185: SourceCodester Hospitals Patient Records Management System SQL injection in Users.php

CVE-2026-10185 · Severity: high · CVSS 7.3 · Published 2026-05-31

Technologies: SourceCodester Hospitals Patient Records Management System. Vendors: SourceCodester.

Executive brief

SourceCodester Hospitals Patient Records Management System 1.0 is vulnerable to a security flaw that allows unauthorized individuals to access or modify the underlying database. This system is used to manage sensitive patient records and hospital administrative data. An attacker could exploit this to steal patient information, alter medical records, or disrupt hospital operations without needing any login credentials.

Technical details

A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System 1.0 within the '/classes/Users.php?f=save' endpoint. The root cause is the improper neutralization of the 'id' parameter, which is used directly in SQL queries without sufficient validation or sanitization. A remote, unauthenticated attacker can exploit this by sending a specially crafted POST request containing a boolean-based blind SQL injection payload. Successful exploitation allows for unauthorized database access, sensitive data exfiltration, and potential data tampering. A public exploit (PoC) has been disclosed.

Affected products

  • SourceCodester Hospitals Patient Records Management System 1.0

Timeline

  • 2026-05-06: disclosed: Initial discovery and report on GitHub by zzb1388.
  • 2026-05-31: advisory: CVE-2026-10185 published.

References

Related threats