{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-85397/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:code_projects:hospital_information_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-85397"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hospital Information System (1.0)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sql-injection","cve-2026-85397","vulnerability","web"],"_cs_type":"advisory","_cs_vendors":["code-projects"],"content_html":"\u003cp\u003eHospital Information System version 1.0 contains a critical SQL injection vulnerability identified as CVE-2026-85397. The flaw resides in the findBySearch function within the addReq.php file. An unauthenticated remote attacker can exploit this by injecting malicious SQL payloads into the Search argument processed by the web application. Successful exploitation could lead to unauthorized database access, data exfiltration, or complete database compromise. As the exploit has been publicly disclosed and is available for use, the risk to organizations running this specific version is significant. Defenders must prioritize identifying and securing any internet-facing instances of this legacy software.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify web servers running Hospital Information System 1.0.\u003c/li\u003e\n\u003cli\u003eAttacker probes for the addReq.php file on the target server.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the Search parameter as a target for injection.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET or POST request containing SQL injection syntax in the Search field.\u003c/li\u003e\n\u003cli\u003eThe application passes the unsanitized input to the database query engine.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected SQL command.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves unauthorized data or modifies database records.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects instances of the Hospital Information System 1.0, typically used within healthcare-related information management contexts. Successful exploitation enables unauthorized access to sensitive healthcare data stored within the backend database. Given the nature of hospital information systems, this could result in widespread exposure of patient records, violation of data privacy regulations, and operational disruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all deployments of Hospital Information System 1.0 within the environment.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block requests containing SQL syntax or common injection patterns (such as ' or -- or UNION SELECT) directed at addReq.php.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect potential exploitation attempts via web server logs.\u003c/li\u003e\n\u003cli\u003eIf a patch is not available from the vendor, isolate the affected application behind an authenticated reverse proxy or disable access to the addReq.php file.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T03:24:35Z","date_published":"2026-09-04T03:24:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85397-sql-injection/","summary":"An unauthenticated SQL injection vulnerability in the Hospital Information System 1.0 allows remote attackers to execute unauthorized database queries via the Search parameter in addReq.php.","title":"SQL Injection Vulnerability in Hospital Information System 1.0","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85397-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-85397","version":"https://jsonfeed.org/version/1.1"}