VYPR

Hospital Information System

by Code Projects

CVEs (8)

  • CVE-2022-36669CriSep 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

  • CVE-2026-85399HigSep 4, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack…

  • CVE-2026-85398HigSep 4, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available…

  • CVE-2026-85397HigSep 4, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-76574HigAug 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack…

  • CVE-2026-86302MedSep 7, 2026
    risk 0.34cvss 5.3epss

    A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote…

  • CVE-2023-37070MedAug 14, 2023
    risk 0.31cvss 4.8epss 0.01

    Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)

  • CVE-2026-86301LowSep 7, 2026
    risk 0.23cvss 3.5epss

    A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may…