CVE-2026-86301: code-projects Hospital Information System Patient Management editPatient.php cross site scripting
Published Sep 7, 2026
·Updated
A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Code-projects Hospital Information System=1.0
Event History
Sep 7, 2026
CVE Published
via MITRE·11:45 AM
Data Sourced
via MITRE·11:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attack can be performed remotely and has low complexity, but the attacker must have low-level privileges and must induce user interaction.
2
What is the expected security impact?
The assessed impact is limited to low integrity impact. No confidentiality or availability impact is indicated.