CVE-2026-10299
LOW
2,0
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
3,8
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: low
MEDIUM
4,7
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: multiple
Confidentiality: none
Integrity: partial
Availability: partial
Description
AI Translation Available
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
99
Improper Control of Resource Identifiers ('Resource Injection')
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Application Data
Modify Application Data
Read Files Or Directories
Modify Files Or Directories
Applicable Platforms
All platforms may be affected
https://code-projects.org/
https://github.com/Carm3nc1ta/vuln-test/blob/main/Online%20Hospital%20Managemen…
https://vuldb.com/cve/CVE-2026-10299
https://vuldb.com/submit/827505
https://vuldb.com/vuln/367592
https://vuldb.com/vuln/367592/cti