Description
A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2026-05-30: | Advisory disclosed |
| 2026-05-30: | VulDB entry created |
| 2026-05-30: | VulDB entry last update |
Credits
yuyuyu (VulDB User)
References
vuldb.com/vuln/367467 (VDB-367467 | code-projects Online Hospital Management System patient.php sql injection)
vuldb.com/vuln/367467/cti (VDB-367467 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10186 (CVE-2026-10186 | CVE Analysis and Report)
vuldb.com/submit/819933 (Submit #819933 | code-projects code-projects Online Hospital Management System 1.0 1.0 SQL Injection)
github.com/aiyuyuyu/cve/blob/main/patient_sql.md
code-projects.org/