Impact
A flaw in the viewappointment.php file of itsourcecode Hospital Management System 1.0 allows an attacker to manipulate the delid argument and inject arbitrary SQL. The injection can be triggered remotely via an HTTP request, potentially enabling the attacker to read, modify, or delete data stored in the underlying database. The CVE notes that an exploit is already published, indicating that the vulnerability is actionable.
Affected Systems
The affected product is itsourcecode Hospital Management System version 1.0. No other versions or variants are listed, and the CPE string confirms that the vulnerability resides in the core application, not in an add‑on or external service.
Risk and Exploitability
The CVSS score of 5.3 categorizes this vulnerability as moderate, while the EPSS score is unspecified. The exploit is listed as not in CISA’s KEV catalog. The attack vector is remote, as the injection is triggered through a web interface. Attackers do not require prior access or credentials; they can target the endpoint directly from any internet‑connected device.
OpenCVE Enrichment