PT-2026-31867 · Code Projects · Patient Record Management System

Userq

·

Published

2026-04-10

·

Updated

2026-04-11

·

CVE-2026-6006

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions code-projects Patient Record Management System version 1.0
Description A SQL injection issue exists in code-projects Patient Record Management System version 1.0. The vulnerability is located in an unknown function within the /edit hpatient.php file. Manipulation of the ID argument can trigger the SQL injection. The attack can be initiated remotely and the exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6006

Affected Products

Patient Record Management System