SQL Injection Vulnerability in Project Worlds Hospital Management System (PHP)
CVE-2026-8785
Key Information:
- Vendor
Projectworlds
- Vendor
- CVE Published:
- 18 May 2026
Badges
What is CVE-2026-8785?
A vulnerability exists in the Project Worlds Hospital Management System in PHP, specifically within the getAllPatientDetail function of the update_info.php file. This flaw arises from improper handling of the appointment_no parameter, which can be manipulated to execute SQL injection attacks. Such attacks are possible remotely, allowing unauthorized access to sensitive patient information. Despite early notifications to the project maintainers regarding this issue, no resolution has been made public. This vulnerability may be exploited by attackers seeking to compromise the integrity and confidentiality of the system.
Affected Version(s)
hospital-management-system-in-php 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
