Impact
The vulnerability resides in the editid parameter of the /servicetype.php file in itsourcecode Hospital Management System 1.0, allowing attackers to inject arbitrary SQL statements. This flaw permits remote exploitation that could lead to unauthorized read, modification, or deletion of database records, directly compromising patient confidentiality and system integrity. The weakness is a classic SQL injection, classified as CWE‑89 and involves improper input neutralization (CWE‑74).
Affected Systems
Itsourcecode Hospital Management System 1.0 is affected. The flaw is located in the servicetype.php component and is present in the default installation of the product. No other versions are reported in the CVE as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available, but the public exploit is available on GitHub and other sites. The vulnerability is not listed in the CISA KEV catalog. It can be exploited remotely via a crafted HTTP request to servicetype.php with a malicious editid parameter. Attackers with network access can trigger SQL injection to compromise data.
OpenCVE Enrichment