CVE-2026-2179
MEDIUMPhpgurukul Hospital Management System - Injection
Title source: ruleDescription
A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Scores
CVSS v3
4.7
EPSS
0.0004
EPSS Percentile
12.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-74
CWE-89
Status
published
Affected Products (1)
phpgurukul/hospital_management_system
Timeline
Published
Feb 08, 2026
Tracked Since
Feb 18, 2026