Description
A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /db/hcpms.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-04-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A weakness has been identified in code-projects Patient Record Management System that allows attackers to read the /db/hcpms.sql backup file. The vulnerability can lead to the exposure of confidential patient data, compromising the confidentiality of the system and potentially violating privacy regulations. The primary weakness is a configuration or permission error that permits unauthorized access to a SQL database backup file; it is not an escalation or code execution flaw but gives attackers direct read access to sensitive information.

Affected Systems

The affected product is code-projects Patient Record Management System, version 1.0, deployed under the vendor code-projects. The flaw resides in the SQL Database Backup File Handler component, which parses or serves the backup file located at /db/hcpms.sql.

Risk and Exploitability

The CVSS base score is 5.3, indicating a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but a publicly available exploit demonstrates that attackers can remotely retrieve the backup file. The attack vector is remote access over the network, and the exploit requires no authentication, making this vulnerability highly accessible to external adversaries.

Generated by OpenCVE AI on April 9, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to the most current release of the Patient Record Management System.
  • Configure the web server or application to deny access to the /db/hcpms.sql file path, or move the backup file outside of the web root.
  • Remove or delete any exposed backup files from publicly accessible directories to eliminate the data exposure vector.
  • Implement file‑permission controls so that only privileged system processes can read backup files.
  • Enable logging of access attempts to the backup file and regularly review logs for suspicious activity.

Generated by OpenCVE AI on April 9, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /db/hcpms.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Title code-projects Patient Record Management System SQL Database Backup File hcpms.sql information disclosure
First Time appeared Code-projects
Code-projects patient Record Management System
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:code-projects:patient_record_management_system:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects patient Record Management System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Patient Record Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-10T14:04:51.221Z

Reserved: 2026-04-09T09:52:49.840Z

Link: CVE-2026-5960

cve-icon Vulnrichment

Updated: 2026-04-10T14:04:48.202Z

cve-icon NVD

Status : Received

Published: 2026-04-09T16:16:36.230

Modified: 2026-04-09T16:16:36.230

Link: CVE-2026-5960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T09:32:26Z

Weaknesses