Junglewise Threat Intelligence

CVE-2026-16014: code-projects Hospital Bed Management System SQL injection in Login Form

CVE-2026-16014 · Severity: high · CVSS 7.3 · Published 2026-07-17

Vendors: Code-Projects.

Executive brief

The Hospital Bed Management System, a web application used for managing medical facility resources, contains a security flaw in its login interface. An attacker can bypass the login screen to gain unauthorized access to the system by entering specially crafted text into the username field. This could allow an unauthorized individual to view or modify sensitive hospital data, potentially disrupting medical operations.

Technical details

A SQL injection vulnerability exists in the Login Form component of code-projects Hospital Bed Management System 1.0. The vulnerability is rooted in the improper neutralization of special elements within the 'Username' input field. A remote, unauthenticated attacker can exploit this by submitting malicious SQL queries through the login interface, leading to an authentication bypass. Successful exploitation allows the attacker to gain administrative or user-level access to the application without valid credentials. Public exploit details have been disclosed, confirming the ability to bypass security controls using classic SQL injection strings.

Affected products

  • code-projects Hospital Bed Management System 1.0

Timeline

  • 2026-06-12: disclosed: Initial discovery and issue report on Gitee
  • 2026-07-17: advisory: NVD/VulDB publication date

References