Impact
The vulnerability is an unchecked SQL injection in the patientlogin.php module of the itsourcecode Hospital Management System, enabled by manipulating the loginid parameter. This flaw falls under CWE-74 and CWE-89 and allows an attacker to inject arbitrary SQL statements, potentially compromising the confidentiality, integrity, and availability of patient data.
Affected Systems
The flaw affects itsourcecode Hospital Management System version 1.0 as published by itsourcecode. No other versions or forks were identified in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while an EPSS score of < 1% suggests a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. The flaw is remotely exploitable through web traffic. Based on the description, it is inferred that an attacker could read, modify or delete patient records, leading to a data breach.
OpenCVE Enrichment