Impact
A flaw in itsourcecode Hospital Management System version 1.0 allows a remote attacker to inject arbitrary SQL code by manipulating the delid argument in the patviewprescription.php page. The injection can lead to execution of arbitrary SQL statements against the backend database, compromising data confidentiality, integrity, and availability. The vulnerability is a classic SQL injection identified by CWE‑74 and CWE‑89.
Affected Systems
The vulnerability affects Hospital Management System version 1.0 from itsourcecode, specifically the patviewprescription.php component that handles the delid parameter. No other products or versions are mentioned.
Risk and Exploitability
The flaw has a CVSS score of 5.3, indicating moderate severity. Its EPSS score is less a low exploitation probability, and it is not listed in the CISA KEV catalog. However, the exploit is publicly available and remote exploitation is possible, meaning that anyone who can reach the web application could potentially manipulate the database. Prompt remediation is therefore advisable.
OpenCVE Enrichment