Impact
A remote attacker can manipulate the delid argument in the /viewdoctor.php page of itsourcecode Hospital Management System, which is processed in a way that allows an SQL injection. The flaw can be exploited by sending specially crafted requests over the network; the input is not properly sanitized before being incorporated into a database query. Successful exploitation may lead to reading, modifying, or deleting sensitive medical data stored in the system's database, turning the vulnerability into a data breach threat.
Affected Systems
The issue affects version 1.0 of itsourcecode Hospital Management System, released by itsourcecode. No other versions or products are explicitly mentioned in the available data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, but the same advisory notes that the exploit is publicly available, which raises the practical risk. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote HTTP requests that target the vulnerable endpoint, with no prerequisite authentication stated in the description.
OpenCVE Enrichment