Impact
The identified flaw resides in an undefined routine within viewdoctorconsultancycharge.php. By supplying a crafted value for the delid parameter, an attacker can inject arbitrary SQL. The injection may allow the attacker to read, modify, or delete data in the hospital’s database, compromising the confidentiality and integrity of sensitive medical information. The vulnerability does not directly grant remote code execution.
Affected Systems
The vulnerability affects the itsourcecode Hospital Management System, version 1.0. No other versions are mentioned in the CVE data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The description states that the injection can be triggered remotely and has been publicly disclosed, which increases the likelihood of exploitation. Attackers can reach the vulnerable PHP file over the network without needing privileged access, making it a low‑barrier risk for attackers who discover the remote endpoint.
OpenCVE Enrichment