---
id: CVE-2026-86301
title: >-
  A vulnerability has been found in code-projects Hospital Information System
  1.0
summary: >-
  A vulnerability has been found in code-projects Hospital Information System
  1.0. Affected is an unknown function of the file
  /HIS/src/patients/editPatient.php of the component Patient Management. Such
  manipulation of the argument ID lead…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: code-projects
product: Hospital Information System
affected:
  - hospital_information_system 1.0
published: '2026-09-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T15:18:53.900'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86301'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Reflected%20Cross-Site%20Scripting%20(XSS)%20in%20Hospital%20Information%20System%20%60id%60%20Parameter.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86301'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/906740'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399465'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399465/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T14:05:13.728786Z'
epss: 0.00199
epssPercentile: 0.09952
ingestedAt: '2026-09-08T15:33:26.976Z'
---

## Overview

A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
