Hospital Information System
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36669 | Cri | 0.64 | 9.8 | 0.02 | Sep 14, 2022 | Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. | ||
| CVE-2026-85399 | Hig | 0.47 | 7.3 | 0.00 | Sep 4, 2026 | A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack… | ||
| CVE-2026-85398 | Hig | 0.47 | 7.3 | 0.00 | Sep 4, 2026 | A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available… | ||
| CVE-2026-85397 | Hig | 0.47 | 7.3 | 0.00 | Sep 4, 2026 | A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been… | ||
| CVE-2026-76574 | Hig | 0.47 | 7.3 | 0.00 | Aug 19, 2026 | A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack… | ||
| CVE-2026-86302 | Med | 0.34 | 5.3 | — | Sep 7, 2026 | A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote… | ||
| CVE-2023-37070 | Med | 0.31 | 4.8 | 0.01 | Aug 14, 2023 | Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS) | ||
| CVE-2026-86301 | Low | 0.23 | 3.5 | — | Sep 7, 2026 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may… |
- risk 0.64cvss 9.8epss 0.02
Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
- risk 0.47cvss 7.3epss 0.00
A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available…
- risk 0.47cvss 7.3epss 0.00
A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been…
- risk 0.47cvss 7.3epss 0.00
A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack…
- risk 0.34cvss 5.3epss —
A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote…
- risk 0.31cvss 4.8epss 0.01
Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)
- risk 0.23cvss 3.5epss —
A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may…