Impact
The vulnerability occurs in Hospital Management System 1.0 within the file /prescriptionorderreport.php. A manipulation of the delid argument enables an attacker to inject arbitrary SQL statements, resulting in unauthorized data disclosure or modification. This weakness arises from improper input handling, classified as CWE-89 (SQL Injection).
Affected Systems
Itsourcecode Hospital Management System version 1.0 is affected. No additional versions or product variants are listed.
Risk and Exploitability
The CVSS score of 5.3 assigns a moderate risk level. EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. The description states the attack may be launched remotely, suggesting an attacker could issue crafted HTTP requests to the vulnerable endpoint. While a publicly disclosed exploit exists, its potential impact remains limited to data tampering rather than full code execution. The overall risk is moderate; however, organizations should verify whether the system is exposed to potential exploitation.
OpenCVE Enrichment