Impact
The vulnerability exists in the /viewadmin.php file of itsourcecode Hospital Management System 1.0, allowing an attacker to manipulate the 'delid' argument. By injecting SQL code into this parameter, an attacker can query, alter, or delete data from the underlying database, potentially leading to data disclosure or modification. The specific effects on data integrity or confidentiality are inferred from the nature of the injection and are not directly stated in the advisory. The weakness is a classic input validation flaw (CWE-74 and CWE-89).
Affected Systems
Itsourcecode Hospital Management System version 1.0 is affected. No other vendor versions are listed in the advisory. The issue resides in the web application layer and is specific to the remaining component of that product.
Risk and Exploitability
The CVSS score of 5.3 classifies this attack as medium severity. EPSS is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The exploit can be performed from a remote location by sending a crafted request to the web server, and the publicly available proof‑of‑concept indicates that attackers can gain arbitrary database access without prior authentication.
OpenCVE Enrichment