A vulnerability was found in PHPGurukul Hospital Management System 4.0 and classified as critical. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Such manipulation of the argument ID leads to sql injection.

This vulnerability is listed as CVE-2026-2134. The attack may be performed from remote. In addition, an exploit is available.