A vulnerability marked as critical has been reported in code-projects Patient Record Management System 1.0. This affects an unknown function of the file /fecalysis_not.php. This manipulation of the argument comp_id causes sql injection.
This vulnerability is handled as CVE-2026-2706. The attack can be initiated remotely. Additionally, an exploit exists.