{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/kishan0725/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kishan0725:hospital_management_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-82914"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hospital-Management-System (1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["kishan0725"],"content_html":"\u003cp\u003eA SQL injection vulnerability has been identified in version 1.0 of the Hospital-Management-System developed by kishan0725. The flaw resides in the handling of the 'Contact' argument within the '/search.php' script, which fails to properly sanitize user-supplied input before incorporating it into database queries. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary SQL commands against the backend database. A public exploit is available, increasing the risk of exploitation. Given that the vendor is unresponsive and no patch exists, defenders should treat this as a high-priority risk for internet-facing instances of this software.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized access to sensitive healthcare data stored in the application database. An attacker could potentially extract, modify, or delete administrative and patient records, leading to a significant data breach or compromise of system integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy web application firewall (WAF) rules to inspect and filter suspicious SQL injection patterns in the 'Contact' parameter of requests directed to '/search.php'. If the system is not critical, restrict access to the application via network-level controls until the vendor releases a security update.\u003c/p\u003e\n","date_modified":"2026-08-31T21:59:47Z","date_published":"2026-08-31T21:59:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-hospital-management-sql-injection/","summary":"The Hospital-Management-System version 1.0 is vulnerable to remote SQL injection via the Contact parameter in /search.php, enabling potential unauthorized data access.","title":"SQL Injection Vulnerability in Hospital-Management-System","url":"https://feed.craftedsignal.io/briefs/2026-08-hospital-management-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Kishan0725","version":"https://jsonfeed.org/version/1.1"}