Impact
The vulnerability is a classic SQL injection in the transaction_details.php script of the onetwothreeneth HospitalManagementSystem. By manipulating the transaction_id parameter, an attacker can inject arbitrary SQL statements. This can lead to unauthorized read, modify, or delete operations on the database, potentially exposing sensitive medical records or corrupting transactional data. The vulnerability was publicly disclosed and can be exploited from a remote source.
Affected Systems
The affected product is the onetwothreeneth HospitalManagementSystem, specifically the transaction_details.php component up to commit 9ef91ed6007314b6473110ed699dff76d158f61d. No explicit version numbers are provided because the project uses a rolling release model without detailed changelog tagging, so any instance that includes this code path before the fix is likely vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, yet it remains publicly exploitable with the information disclosed. Since the flaw can be triggered remotely and the vendor has not yet released a patch, the likelihood of exploitation is significant for any system still running the pre‑fix code. Effective mitigation requires addressing the input handling flaw and monitoring for injection attempts.
OpenCVE Enrichment