Impact
A vulnerability in the treatmentdetail.php file of itsourcecode Hospital Management System allows attackers to inject arbitrary SQL via the patientid parameter when the application processes requests. The injection occurs without proper filtering or parameterization, enabling remote attackers to read or alter data stored in the backend database. The CVSS score of 5.3 signifies moderate impact; if exploited, an attacker could gain unauthorized access to sensitive patient information or modify records, affecting data confidentiality and integrity.
Affected Systems
The affected product is itsourcecode Hospital Management System version 1.0. No further subversion details are available. The vulnerability is reported for the root domain of the application, and the affected path is /treatmentdetail.php.
Risk and Exploitability
With a CVSS score of 5.3, the risk is moderate. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no public exploitation has been reported. The attack vector is remote, as the flaw can be triggered by sending a crafted HTTP request containing a malicious patientid value. Successful exploitation would require access to the web application—either authenticated or unauthenticated sessions—depending on existing access controls.
OpenCVE Enrichment