CVE-2026-2179

MEDIUM

Phpgurukul Hospital Management System - Injection

Title source: rule

Description

A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 4.7
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-74 CWE-89
Status published

Affected Products (1)

phpgurukul/hospital_management_system

Timeline

Published Feb 08, 2026
Tracked Since Feb 18, 2026