Impact
This vulnerability allows an attacker to manipulate the ID parameter in the /admin/manage-users.php script of PHPGurukul Hospital Management System version 4.0, resulting in an uncontrolled SQL injection. The input is not validated or safely bound, permitting the execution of arbitrary SQL commands against the system’s database.
Affected Systems
The issue affects installations of PHPGurukul Hospital Management System version 4.0, specifically the /admin/manage-users.php functionality used for user management.
Risk and Exploitability
The CVSS score of 5.1 indicates medium severity. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack can be initiated remotely by supplying a crafted ID value to the /admin/manage-users.php endpoint; authentication prerequisites are not specified in the description, so the risk depends on how exposed the endpoint is.
OpenCVE Enrichment