Impact
A vulnerable parameter, patientid, in the payment.php script of itsourcecode Hospital Management System 1.0 can be manipulated to inject arbitrary SQL. The flaw permits an attacker to potentially retrieve, modify, or delete data. This weakness is associated with CWE‑89 (SQL Injection) and undermines the confidentiality and integrity of data stored in the system.
Affected Systems
The vulnerability impacts version 1.0 of Hospital Management System from itsourcecode. It is present in the payment.php component and any installations running this version are susceptible. No later versions are listed as affected, and no details of patch availability are provided in the supplied data.
Risk and Exploitability
The CVSS v3 score of 5.3 indicates moderate severity. The EPSS score of less than 1 % shows a very low probability of exploitation, yet a public exploit can be triggered remotely over the network. The vulnerability is not recorded in the CISA KEV catalog, implying no widespread attack campaigns currently documented.
OpenCVE Enrichment