Impact
Hospital Management System plugin for WordPress has an unvalidated input that is concatenated into SQL queries, allowing an attacker to inject arbitrary SQL. The flaw enables unauthorized read, modification, or deletion of database records, potentially exposing or corrupting sensitive patient and administrative data. The weakness is a classic SQL injection (CWE‑89) that can compromise the confidentiality and integrity of the site’s data.
Affected Systems
Known affected editions are Mojoomla’s Hospital Management System plugin, version 47.0 released on 20 November 2023 or any earlier release identified as n/a through that date. All installations that have not applied a later update are vulnerable.
Risk and Exploitability
The CVSS v3 score of 9.3 classifies the issue as critical, while the EPSS score of less than 1% suggests a low likelihood of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw remotely, likely by submitting crafted input through the plugin’s exposed web forms or API endpoints without needing authentication, which would allow them to inject malicious SQL code into the database. No public exploit is documented, but the high severity warrants immediate attention.
OpenCVE Enrichment
EUVD