Impact
The vulnerability is an improper neutralization of special characters in SQL statements within the Hospital Management System plugin for WordPress, which allows an unauthenticated attacker to inject arbitrary SQL. This flaw can result in unauthorized reading, modification, or deletion of data stored in the application's database, compromising confidentiality, integrity, and potentially availability if the database is disrupted.
Affected Systems
The affected product is the Mojoomla Hospital Management System plugin for WordPress. Versions from the initial release through and including 47.0 released on 20‑11‑2023 contain the flaw.
Risk and Exploitability
With a CVSS score of 8.5 the flaw is considered high severity. The EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, via an HTTP request containing a malicious payload to a vulnerable endpoint in the plugin.
OpenCVE Enrichment
EUVD