Description
A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_print.php. Executing a manipulation of the argument hem_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2026-04-09: | Advisory disclosed |
| 2026-04-09: | VulDB entry created |
| 2026-04-09: | VulDB entry last update |
Credits
userq (VulDB User)
References
vuldb.com/vuln/356561 (VDB-356561 | code-projects Patient Record Management System hematology_print.php sql injection)
vuldb.com/vuln/356561/cti (VDB-356561 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/794536 (Submit #794536 | code-projects Health Care Patient Record Management System 1.0 SQL Injection)
github.com/1768161086/SQL_CVE_1.0/blob/main/sql_cve.pdf
code-projects.org/