Impact
A vulnerability exists in itsourcecode Hospital Management System 1.0 in the /viewpatient.php file. An attacker can manipulate the delid parameter to inject arbitrary SQL statements into the database. The injection flaw allows remote attackers to send crafted HTTP requests, potentially enabling unauthorized data retrieval, modification, or deletion. The impact is a loss of confidentiality and integrity of patient data and may lead to broader database compromise.
Affected Systems
Itsourcecode Hospital Management System version 1.0. The vulnerable component is the viewpatient.php file that processes the delid parameter. No other versions or products are currently reported as affected.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploitation but the flaw is publicly disclosed. The attacker can exploit the flaw remotely by supplying a malicious delid value in an HTTP request to the susceptible endpoint. Because the flaw is a classic SQL injection, successful exploitation depends on the database configuration and the privileges of the application database user.
OpenCVE Enrichment