CVE-2026-85397: code-projects Hospital Information System addReq.php findBySearch sql injection
Published Sep 4, 2026
·Updated
A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
1 affected component
Code-projects Hospital Information System=1.0
Event History
Sep 4, 2026
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
No. The vector indicates network-accessible exploitation with low attack complexity, no privileges required, and no user interaction required.
2
What is the potential impact of successful exploitation?
Successful SQL injection may affect confidentiality, integrity, and availability at a low impact level for each. The issue is rated high severity with a 7.3 CVSS score.
3
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used by attackers.