Impact
A SQL injection flaw exists in the viewpaymentreport.php file of Hospital Management System 1.0 when the delid argument is manipulated. The vulnerability enables a remote attacker to inject arbitrary SQL commands, potentially leading to unauthorized data read, alteration, or deletion. This is a classic injection weakness identified as CWE‑74 and CWE‑89, indicating the lack of input validation and failure to use safe query mechanisms.
Affected Systems
The affected product is itsourcecode Hospital Management System 1.0. No other versions are specified in the advisory, so only this version appears to be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the exploit probability is unknown but the existence of a public exploit indicates a non‑zero risk. The vulnerability is not listed in CISA KEV, but an attacker can still launch the attack from any network path that can reach the application because the flaw is remotely exploitable.
OpenCVE Enrichment