Impact
The vulnerability is a SQL injection in the viewdoctortimings.php page of itsourcecode Hospital Management System. By manipulating the delid argument supplied by an HTTP request, an attacker can alter the SQL query executed by the application. This creates a pathway for unauthorized access to or modification of database contents, potentially exposing sensitive patient and staff information and disrupting clinic operations.
Affected Systems
The flaw affects itsourcecode Hospital Management System version 1.0. No other versions or variants are listed. The problematic logic resides in the processing of the viewdoctortimings.php file when the delid parameter is provided.
Risk and Exploitability
The CVSS score of 5.3 classifies the flaw as medium severity, and the EPSS score is not available, indicating an unquantified but potentially moderate exploitation likelihood. The vulnerability can be triggered from a remote HTTP request, and public exploits have been released on GitHub. Because the description states the attack can be performed from remote and no authentication requirement is mentioned, an exposed installation may be at risk of data theft, accidental or intentional data alteration, and a possible denial of service through resource exhaustion. The vulnerability is not listed in the CISA KEV catalog, but its availability online warrants proactive attention.
OpenCVE Enrichment