Impact
A SQL injection vulnerability exists in /viewroom.php when the delid parameter is manipulated. By inserting specially crafted payloads the attacker can alter or retrieve data from the database, potentially disrupting the hospital management system and exposing sensitive patient information.
Affected Systems
itsourcecode Hospital Management System version 1.0, accessed via the viewroom.php page.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting no publicly available exploit. Attackers can reach the vulnerable endpoint remotely, possibly leveraging public exposure to craft and send malicious requests to the delid parameter.
OpenCVE Enrichment