Executive brief
code-projects Hospital Information System is a web-based healthcare management application. A critical flaw exposes the SQL database backup file at a predictable location, allowing attackers to download the entire database containing patient records and sensitive hospital data without authentication. This leads to potential exposure of protected health information (PHI) and privacy violations.
Technical details
The vulnerability is an information disclosure flaw in the SQL Database Backup File Handler component. The file /HIS/his.sql is stored in a web-accessible location without proper access controls, enabling unauthenticated remote retrieval of the entire database. An attacker can directly request the backup file via HTTP to exfiltrate all database contents, including patient personal information, medical records, and administrative credentials. The vulnerability requires no authentication and is remotely exploitable via the network. No vendor patch has been released as of the advisory date.
Affected products
- code-projects Hospital Information System 1.0
Timeline
- 2026-09-07: disclosed