Junglewise Threat Intelligence

CVE-2026-8785: Project Worlds Hospital Management System SQL injection in update_info.php

CVE-2026-8785 · Severity: high · CVSS 7.3 · Published 2026-05-18

Executive brief

A security vulnerability exists in the Project Worlds Hospital Management System, a software package used to manage patient records and appointments. An attacker can exploit this flaw to bypass security controls and gain unauthorized access to the hospital's database. This could result in the theft of sensitive patient information, including medical conditions, contact details, and addresses, or the disruption of hospital operations.

Technical details

A critical SQL injection vulnerability exists in the getAllPatientDetail function within update_info.php of Project Worlds Hospital Management System 1.0. The root cause is twofold: the application fails to properly sanitize the 'appointment_no' GET parameter (relying on htmlentities() for numeric contexts) and suffers from broken access control where PHP execution continues after a failed JavaScript-based authentication check. A remote, unauthenticated attacker can exploit this by sending crafted SQL queries to the server, potentially leading to full database compromise and extraction of sensitive patient data. While a public exploit and proof-of-concept are available, the vendor has not yet released a patch; developers are advised to implement prepared statements and ensure server-side script termination (exit) after redirects.

Affected products

  • Project Worlds Hospital Management System in PHP 1.0

Timeline

  • 2026-04-24: disclosed: Vulnerability reported to vendor via GitHub issue
  • 2026-05-18: advisory: Vulnerability published in NVD/VulDB

References