CVE-2026-5960 is a vulnerability in code-projects Patient Record Management System version 1.0 affecting the SQL Database Backup File Handler component. The weakness resides in the /db/hcpms.sql backup file and enables unauthorized information disclosure through database manipulation. The vulnerability presents a medium-severity risk with a CVSS score of 4.3. It is network-accessible, requires no authentication or special privileges, and can be exploited remotely with low attack complexity. However, user interaction is required for successful exploitation, and the impact is limited to confidentiality breaches with no integrity or availability consequences. Exploit code has been publicly released, escalating the risk of opportunistic attacks. However, the vulnerability is not currently tracked on the Known Exploited Vulnerabilities list and shows low community attention based on the inactive hot list status. The EPSS score of 0.00034 indicates minimal probability of exploitation in the wild relative to other CVEs, suggesting limited immediate threat despite public exploit availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Code-Projects | Patient Record Management System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.