Impact
A flaw exists in the patient.php page of itsourcecode Hospital Management System where the editid argument is processed without proper sanitization. By manipulating this parameter, an attacker can inject arbitrary SQL statements. The injection can affect the as CWE-89 and CWE-74.
Affected Systems
Itsourcecode Hospital Management System is affected; any installation of this the network is at risk.
Risk and Exploitability
Based on the description, the likely attack vector is a remote HTTP request to the patient.php endpoint, requiring network connectivity to the management server and the ability to craft a malicious editid value. The CVSS base score of 5.3 indicates moderate impact, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Though publicly disclosed, the existence of a published exploit warrants proactive mitigation.
OpenCVE Enrichment