MEDIUM 5.5 NVD
CVE-2026-85399
A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file
A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
References
- https://code-projects.org/
- https://github.com/lccc-t/CVE/issues/4
- https://vuldb.com/cve/CVE-2026-85399
- https://vuldb.com/submit/894860
- https://vuldb.com/vuln/398542
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-09-04 via NVD.
vulnfeed aggregates 7585 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.