Impact
The vulnerability is an SQL injection in the /prescriptionrecord.php script of itsourcecode Hospital Management System. By manipulating the delid argument, an attacker can inject arbitrary SQL altering, or deleting sensitive patient data. The flaw directly compromises the confidentiality and integrity of the system because the injected statements run with the privileges of the database account used by the application.
Affected Systems
itsourcecode Hospital Management System version 1.0 is affected, specifically the prescriptionrecord.php component that processes the delid parameter. No other versions or modules are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. However, the vulnerability can be engaged remotely via an HTTP request and a public exploit is available, so a potential attacker can launch an attack without any special access. Because it is not listed in the CISA KEV catalog, no large‑scale exploitation has been reported yet, but the remote nature and public exploitability keep the risk noticeable for exposed installations.
OpenCVE Enrichment