Junglewise Threat Intelligence

CVE-2026-6006: code-projects Patient Record Management System SQL injection in edit_hpatient.php

CVE-2026-6006 · Severity: medium · CVSS 6.3 · Published 2026-04-10

Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the Patient Record Management System, a software used to manage healthcare patient data. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view, modify, or delete sensitive medical records. This could lead to significant data breaches, loss of patient privacy, and disruption of healthcare operations.

Technical details

A SQL injection vulnerability (CWE-89) exists in code-projects Patient Record Management System 1.0. The flaw is located in the /edit_hpatient.php file and is triggered by manipulating the 'ID' parameter. The vulnerability is reachable over the network and requires low-level authentication (PR:L). Successful exploitation allows an attacker to execute arbitrary SQL commands against the backend database, potentially leading to unauthorized data disclosure, modification, or deletion. A public exploit has been disclosed, increasing the risk of exploitation.

Affected products

  • code-projects Patient Record Management System 1.0

Timeline

  • 2026-04-10: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-04-10: advisory: CVE-2026-6006 published.

References