PT-2026-41633 · Unknown · Hospital Management System In Php
Luther
·
Published
2026-05-18
·
Updated
2026-05-18
·
CVE-2026-8785
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
hospital-management-system-in-php version 1.0
Description
A remote SQL injection flaw exists in the GET Parameter Handler component. The issue occurs within the
getAllPatientDetail() function located in the update info.php file, where manipulation of the appointment no parameter allows for the execution of arbitrary SQL commands.Recommendations
As a temporary workaround, restrict access to the
update info.php file or avoid using the appointment no parameter until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hospital Management System In Php