Impact
The vulnerability is a SQL injection flaw in the /betweendates-detailsreports.php endpoint of Hospital Management System 4.0. It permits an attacker to inject arbitrary SQL commands, which can lead to unauthorized data disclosure, data tampering, or, in some configurations, full database compromise. The CWE classification is CWE‑89, indicating a classic input validation weakness. No functionality that could directly trigger remote code execution is described, but the ability to alter or exfiltrate sensitive data represents a serious breach of confidentiality and integrity.
Affected Systems
All installations of Hospital Management System 4.0 are affected, as the vulnerability resides in the core application code and no version filtering is provided. The product name is Hospital Management System 4.0; vendor information is not supplied, so any instance running this version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as Critical, and the EPSS score of less than 1% suggests that, while currently rare, exploitation is possible and could occur if attackers focus on this niche application. The vulnerability is not listed in CISA's KEV catalog, so no public exploits are confirmed, but the lack of defensive mitigations in the application could still allow successful attacks via crafted HTTP requests to the vulnerable endpoint.
OpenCVE Enrichment