CVE-2026-10299

LOW

Online Hospital Management System 1.0 - IDOR via viewdoctortimings.php delid Parameter

Title source: llm
STIX 2.1

Description

A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/vuln/367592
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/vuln/367592/cti
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/cve/CVE-2026-10299
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/submit/827505
Various Sources product
https://code-projects.org/

Scores

CVSS v3 3.8
EPSS 0.0007
EPSS Percentile 20.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-99
Status published
Products (1)
code-projects/Online Hospital Management System 1.0
Published Jun 01, 2026
Tracked Since Jun 02, 2026