Junglewise Threat Intelligence

CVE-2026-10299: code-projects Online Hospital Management System IDOR in viewdoctortimings.php

CVE-2026-10299 · Severity: low · CVSS 3.8 · Published 2026-06-01

Technologies: Code-Projects Online Hospital Management System. Vendors: Code-Projects.

Executive brief

A vulnerability exists in the Online Hospital Management System, a web application used for managing medical facility operations. An attacker can exploit this flaw to delete doctor schedule records that do not belong to them. This can lead to significant operational disruption, including the loss of appointment data and conflicts in hospital scheduling.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the 'viewdoctortimings.php' file of the Online Hospital Management System 1.0. The application fails to perform ownership or authorization checks when processing the 'delid' GET parameter used for deleting doctor timing records. An attacker can manipulate this parameter to delete arbitrary records from the 'doctor_timings' database table. While the reported CVSS indicates high privileges are required, the technical analysis suggests the endpoint may lack session validation entirely, potentially allowing unauthenticated remote attackers to perform mass deletion of schedule data via IDOR enumeration.

Affected products

  • code-projects Online Hospital Management System 1.0

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory

References

Related threats