PT-2026-45196 · Sourcecodester · Hospital'S Patient Records Management System

Zengxingqin

·

Published

2026-05-31

·

Updated

2026-05-31

·

CVE-2026-10185

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-10185

Affected Products

Hospital'S Patient Records Management System