CVE-2026-10299
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.27%
- CWE
- CWE-99
- Published
- 2026-06-01
- Last modified
- 2026-06-02
Affected products
- code-projects Online Hospital Management System
Weakness type
Related vulnerabilities
- CVE-2026-81524 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
- CVE-2026-81521 — Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver
- CVE-2026-62910 — Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2026-15186 — macrozheng mall Portal Endpoint create resource injection
- CVE-2026-13493 — AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection
- CVE-2026-12207 — medkey-org medkey HTTP REST API PatientController.php actionGetPatientById resource injection
- CVE-2026-10624 — SourceCodester Human Resource Management Employee View detailview.php resource injection
- CVE-2026-10168 — OUSL-GROUP-BrinaryBrains School Student Management System Parents.php marks resource injection