Impact
An unsanitized parameter called delid in the viewprescriptionrecord.php page is used in a database query, allowing an attacker to inject arbitrary SQL. The resulting injected code can read, modify or delete prescription records, compromising confidentiality, integrity, and potentially availability of patient data.
Affected Systems
The vulnerability exists in itsourcecode Hospital Management System version 1.0. The affected code is located in the viewprescriptionrecord.php file and the specific function that processes the delid argument is not identified in the advisory. System owners running this version should verify that the application is exposed to the internet and that the delid parameter can be supplied by remote users.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, so the probability of exploitation is unknown. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, and no public exploits were cited, but the attack vector is remote and the vulnerability is public. Consequently, the risk is that an unauthenticated malicious actor could use this flaw until a patch or mitigations are applied.
OpenCVE Enrichment