SQL Injection Flaw in Hospital Information System by Code-Projects
CVE-2026-76574
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 19 August 2026
Badges
What is CVE-2026-76574?
A vulnerability exists in the Hospital Information System version 1.0, specifically in the User::login function within the UsersController.php file. This flaw permits attackers to manipulate the email argument, thereby leading to SQL injection vulnerabilities. The exploitation of this issue can be executed remotely, potentially compromising sensitive user data and system integrity. The exploit has been made publically available, raising concerns for those using this software version.
Affected Version(s)
Hospital Information System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
