Junglewise Threat Intelligence

CVE-2026-9342: SourceCodester Hospitals Patient Records Management System SQL injection in view_history.php

CVE-2026-9342 · Severity: medium · CVSS 6.3 · Published 2026-05-23

Technologies: SourceCodester Hospitals Patient Records Management System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Hospitals Patient Records Management System, a web application used for managing medical patient data. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive patient records, data tampering, or service disruption. This issue is particularly serious as proof-of-concept exploit code has been made publicly available.

Technical details

A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System 1.0 within the '/admin/patients/view_history.php' file. The root cause is the improper neutralization of the 'id' GET parameter before its use in a database query. A remote attacker can exploit this by sending crafted SQL queries (including boolean-based blind, time-based blind, and UNION-based techniques) to the server. Successful exploitation allows for unauthorized database access, sensitive data extraction, and potential modification of patient records. While some reports suggest low privileges are required, others indicate no authentication is necessary to reach the vulnerable endpoint. Public exploit code (PoC) is available.

Affected products

  • SourceCodester Hospitals Patient Records Management System 1.0

Timeline

  • 2026-04-25: disclosed: Vulnerability details and PoC published on GitHub.
  • 2026-05-23: advisory: CVE published and listed on NVD/VulDB.

References

Related threats