Impact
The flaw in prescriptionorderdetail.php allows an attacker to provide a crafted value for the delid argument that is incorporated directly into a SQL statement, enabling the execution of arbitrary SQL code against the database. The vulnerability can be triggered by sending an HTTP request to the affected file from a remote host. The CVE description does not specify whether authentication or elevated privileges are required, so the necessary access level remains uncertain.
Affected Systems
The vulnerability exists only in the itsourcecode Hospital Management System version 1.0. No other vendors, products, or versions are mentioned as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit the flaw remotely by sending a carefully crafted HTTP request to prescriptionorderdetail.php containing a malicious delid value. The description does not state whether authentication or privileges are required, leaving that requirement unknown.
OpenCVE Enrichment