Impact
The vulnerability resides in the login form of code‑projects Hospital Bed Management System 1.0, allowing an attacker to supply a crafted Username value that is inserted directly into an SQL query. This flaw permits arbitrary SQL commands to be executed against the database, enabling attackers to read sensitive data, modify records, or bypass authentication. The weakness is a classic SQL injection described by CWE‑74 and CWE‑89.
Affected Systems
The affected product is code‑projects Hospital Bed Management System version 1.0. No other versions are identified as vulnerable; the problem is confined to the login component of this release.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, but the EPSS score of < 1 % suggests a low overall probability of exploitation. The vulnerability has been made public and is exploitable remotely via the web interface, so exposed deployments remain at risk. The issue is not listed in the CISA KEV catalog; however, publicly available exploit code reduces the barrier to targeted attacks.
OpenCVE Enrichment