Description
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Published: 2026-02-24
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the check_profile_old.php file of the E-Logbook with Health Monitoring System for COVID-19. An attacker can manipulate the profile_id argument to inject arbitrary SQL statements. Successful exploitation can lead to unauthorized read or modification of the database, potentially exposing sensitive health data or corrupting records.

Affected Systems

Affected systems include the vendor itsourcecode's E-Logbook with Health Monitoring System for COVID-19 version 1.0. The issue arises in an unknown code block within the check_profile_old.php script.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score below 1% shows a low probability of current exploitation. The vulnerability is not listed in KEV. Remote exploitation is feasible by sending crafted requests to the vulnerable endpoint. The attack vector appears to rely on external network access to the web application.

Generated by OpenCVE AI on April 17, 2026 at 16:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify that the application has been updated to a version where the SQL injection in check_profile_old.php is remediated; if no update exists, coordinate with the vendor to schedule a fix.
  • Implement strict input validation on the profile_id parameter to reject non‑numeric or unexpected characters.
  • Use parameterized queries or stored procedures for database access instead of concatenated SQL strings.
  • Restrict exposure of the affected endpoint to trusted IP ranges or implement web‑application firewall rules to block suspicious requests.

Generated by OpenCVE AI on April 17, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Feb 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Emiloi
Emiloi e-logbook With Health Monitoring System For Covid-19
CPEs cpe:2.3:a:emiloi:e-logbook_with_health_monitoring_system_for_covid-19:1.0:*:*:*:*:*:*:*
Vendors & Products Emiloi
Emiloi e-logbook With Health Monitoring System For Covid-19

Tue, 24 Feb 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode e-logbook With Health Monitoring System For Covid-19
Vendors & Products Itsourcecode
Itsourcecode e-logbook With Health Monitoring System For Covid-19

Tue, 24 Feb 2026 00:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Title itsourcecode E-Logbook with Health Monitoring System for COVID-19 check_profile_old.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Emiloi E-logbook With Health Monitoring System For Covid-19
Itsourcecode E-logbook With Health Monitoring System For Covid-19
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-26T14:44:29.729Z

Reserved: 2026-02-23T17:30:46.406Z

Link: CVE-2026-3046

cve-icon Vulnrichment

Updated: 2026-02-26T14:44:22.432Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-24T01:16:15.873

Modified: 2026-02-25T20:15:57.470

Link: CVE-2026-3046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T16:15:22Z

Weaknesses