Impact
A flaw in the prescription.php page of itsourcecode Hospital Management System version 1.0 permits an attacker to inject arbitrary SQL via the editid parameter. This control is not constrained to local execution; the injection can be triggered remotely, enabling unauthorized access to, or modification of, patient records and other database contents. The vulnerability is a classic SQL injection (CWE‑74/CWE‑89) that could lead to data breach and integrity violations.
Affected Systems
The affected product is itsourcecode Hospital Management System 1.0. The vulnerability resides in the prescription.php component, specifically the handling of the editid argument. Users of this version that expose the module to the internet are directly vulnerable.
Risk and Exploitability
The CVSS score of 5.3 classifies the flaw as moderate severity. The EPSS indicator is below 1 %, suggesting a low probability of exploitation but the existence of publicly released exploits increases risk. Because the flaw is accessible remotely and can access sensitive medical data, administrators should treat it as material. The vulnerability is not present in the CISA KEV catalog; however, its public exploit availability and remote nature mean that an attacker could potentially subvert patient confidentiality and data integrity without any prior access.
OpenCVE Enrichment