CVE-2026-82914: kishan0725 Hospital-Management-System search.php sql injection
A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is remotely exploitable and requires no privileges or user interaction. An attacker able to reach the affected application's search.php endpoint can target the Contact argument.
Which deployments are known to be affected?
The reported affected product is kishan0725 Hospital-Management-System version 1.0. The available information does not identify configuration prerequisites or indicate whether any particular deployment setup avoids exposure.
What is the immediate risk if the application is exposed?
Public exploit code is available, increasing the likelihood of attempted exploitation. Successful SQL injection may affect confidentiality, integrity, and availability, each with low assessed impact.
What can be done if a vendor fix is not available?
The vendor reportedly did not respond to early contact, and no patch or workaround is provided in the available information. Restrict remote access to the application, especially the search.php endpoint, until a verified remediation is available.
How can defenders look for exploitation attempts?
Review web and application logs for requests to /search.php containing unusual or SQL-like values in the Contact parameter. The available information does not provide specific payloads, indicators, or database error patterns.