Junglewise Threat Intelligence

CVE-2026-6005: code-projects Patient Record Management System SQL injection in hematology_print.php

CVE-2026-6005 · Severity: medium · CVSS 6.3 · Published 2026-04-10

Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the code-projects Patient Record Management System, a software used for managing medical patient data. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view, modify, or delete sensitive medical records. This could lead to significant data breaches, loss of patient confidentiality, and disruption of healthcare operations.

Technical details

A SQL injection vulnerability exists in code-projects Patient Record Management System 1.0 within the file /hematology_print.php. The application fails to properly sanitize the 'hem_id' parameter before using it in a database query. A remote attacker with low-level privileges can manipulate this argument to execute arbitrary SQL commands. This can result in unauthorized data retrieval, modification, or deletion from the database. A public exploit has been disclosed, increasing the risk of exploitation.

Affected products

  • code-projects Patient Record Management System 1.0

Timeline

  • 2026-04-10: disclosed: Initial disclosure and CVE assignment
  • 2026-04-10: advisory: VulDB advisory published

References