


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipu…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 03:00:30
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Database & Storage
A SQL injection vulnerability has been discovered in code-projects Online Hospital Management System affecting version 1.php. The flaw exists in the login_user function within the login_1.php file, where manipulation of the Username parameter leads to SQL injection. The vulnerability can be exploited remotely and a working exploit has been publicly released. This affects healthcare management systems and poses a significant security risk due to the sensitive nature of medical data.
Technical details
Mitigation steps:
Affected products:
Online Hospital Management System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10208
https://code-projects.org/
https://github.com/Mi0uno/Online-Hospital-Management-System-has-SQL-Injection
https://vuldb.com/cve/CVE-2026-10208
https://vuldb.com/submit/821888
https://vuldb.com/vuln/367487
https://vuldb.com/vuln/367487/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
