Impact
A flaw in itsourcecode Hospital Management System version 1.0 allows an attacker to inject arbitrary SQL through the editid parameter in treatment.php, leading to unauthorized database access and data tampering. The vulnerability is a classic input validation weakness (CWE-74) compounded by SQL injection (CWE-89), enabling changes to patient records, extraction of sensitive data, and potential further escalation if the database is privileged.
Affected Systems
The affected product is itsourcecode Hospital Management System, specifically the treatment.php component in version 1.0. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, but the vulnerability has a public exploit available, suggesting a realistic attack likelihood. It is not listed in the CISA KEV catalog yet, but the presence of released payloads makes it a potential threat for systems that have not applied a patch or mitigated the input flaw.
OpenCVE Enrichment