A vulnerability categorized as critical has been discovered in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection.

This vulnerability is documented as CVE-2026-10186. The attack can be executed remotely. Additionally, an exploit exists.