Impact
Care2x Hospital Information Management System 2.7 contains multiple SQL injection flaws that allow attackers to inject arbitrary SQL through the ck_config cookie. When this cookie is manipulated in requests to login.php, indexframe.php, and other module endpoints, the system executes the injected statements, enabling the attacker to read, modify, or delete sensitive database content without authentication.
Affected Systems
Care2x Hospital Information Management System, version 2.7 (alpha). The application is deployed on web servers hosting the aforementioned endpoints.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8 and has no publicly available EPSS value, but its asymmetrical exploit path (unauthenticated HTTP cookie manipulation) indicates that exploitation can be performed remotely by simply setting a crafted ck_config value and navigating to any vulnerable endpoint. Because the flaw is not listed in CISA KEV, no proven exploitation is documented, yet the high severity and lack of authentication barrier make it a high-risk asset if not patched.
OpenCVE Enrichment