Junglewise Threat Intelligence

CVE-2026-10186: code-projects Online Hospital Management System SQL injection in patient.php

CVE-2026-10186 · Severity: high · CVSS 7.3 · Published 2026-05-31

Technologies: Code-Projects Online Hospital Management System. Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the Online Hospital Management System, a web application used for managing medical facility records. An attacker can exploit this flaw to access, modify, or delete sensitive patient information without needing a username or password. This could lead to significant data breaches, loss of patient privacy, and disruption of hospital operations.

Technical details

A SQL injection vulnerability exists in code-projects Online Hospital Management System 1.0 within the 'patient.php' file. The 'editid' parameter is directly concatenated into SQL SELECT and UPDATE queries without sanitization or the use of parameterized statements. Because the affected file lacks authentication checks, a remote, unauthenticated attacker can exploit this flaw to perform unauthorized database operations. This allows for the extraction of sensitive data, modification of existing records, or potential bypass of other security controls. A public exploit has been disclosed.

Affected products

  • code-projects Online Hospital Management System 1.0

Timeline

  • 2026-05-31: disclosed: Public disclosure of the exploit and vulnerability details.
  • 2026-05-31: advisory: NVD and VulDB published the vulnerability record.

References

Related threats