Junglewise Threat Intelligence

CVE-2026-86302: code-projects Hospital Information System information disclosure via SQL backup

CVE-2026-86302 · Severity: medium · CVSS 5.3 · Published 2026-09-07

Technologies: Code-Projects Hospital Information System. Vendors: Code-Projects.

Executive brief

code-projects Hospital Information System is a web-based healthcare management application. A critical flaw exposes the SQL database backup file at a predictable location, allowing attackers to download the entire database containing patient records and sensitive hospital data without authentication. This leads to potential exposure of protected health information (PHI) and privacy violations.

Technical details

The vulnerability is an information disclosure flaw in the SQL Database Backup File Handler component. The file /HIS/his.sql is stored in a web-accessible location without proper access controls, enabling unauthenticated remote retrieval of the entire database. An attacker can directly request the backup file via HTTP to exfiltrate all database contents, including patient personal information, medical records, and administrative credentials. The vulnerability requires no authentication and is remotely exploitable via the network. No vendor patch has been released as of the advisory date.

Affected products

  • code-projects Hospital Information System 1.0

Timeline

  • 2026-09-07: disclosed

References

Related threats