PT-2026-42913 · Sourcecodester · Hospital'S Patient Records Management System

Wuyan-Set

·

Published

2026-05-24

·

Updated

2026-05-24

·

CVE-2026-9355

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save patient history. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-9355

Affected Products

Hospital'S Patient Records Management System