PT-2026-42914 · Sourcecodester · Hospital'S Patient Records Management System

Wuyan-Set

·

Published

2026-05-24

·

Updated

2026-05-24

·

CVE-2026-9356

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin/patients/manage history.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Exploit

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-9356

Affected Products

Hospital'S Patient Records Management System