Impact
A vulnerability was discovered in SourceCodester Hospitals Patient Records Management System 1.0. The bug resides in an unvalidated input handling function within the file /classes/Users.php?f=save. By manipulating the ID argument, an attacker can inject arbitrary SQL statements, allowing unauthorized read, modification, and deletion of patient data stored in the database. The flaw permits remote exploitation; an attacker does not need elevated privileges on the server to trigger it, as the web interface accepts external input directly.
Affected Systems
The affected product is the SourceCodester Hospitals Patient Records Management System, version 1.0, an open‑source application distributed through SourceCodester and maintained under a permissive license. No other versions or variants were explicitly identified in the advisory.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and no EPSS score is available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it remotely by supplying a crafted ID value through the web interface; a public exploit has already been released, indicating that compromised systems could be impacted without significant additional effort.
OpenCVE Enrichment