Impact
The vulnerability is an SQL injection flaw in the get function of print.php. By manipulating the transaction_id argument, an attacker can inject arbitrary SQL code, potentially reading, modifying or deleting data stored in the underlying database. The flaw arises from inadequate input validation (CWE-74) and the direct construction of an SQL query string (CWE-89).
Affected Systems
The affected component is the HospitalManagementSystem developed by onetwothreeneth. The function in the print.php file accepts a transaction_id parameter without proper sanitization. Because the project uses a rolling release model, no fixed commit or release version has been published yet, meaning that any installation built prior to the commit identified as 9ef91ed6007314b6473110ed699dff76d158f61d is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The vulnerability can be exploited remotely, and public exploit code is available, making it a tangible threat to deployed instances. The EPSS score is not provided, so the exploitation probability is uncertain; however, the simple remote attack path and lack of response from maintainers increase the likelihood that the flaw will be abused. The issue is not listed in CISA's KEV catalog, but its remote nature and public exploit make it a priority for remediation.
OpenCVE Enrichment