Impact
A flaw in the viewdepartment.php file of itsourcecode Hospital Management System allows an attacker to modify the delid argument, leading to a classic SQL injection. This issue is exploitable remotely through a web request, and a public exploit has already been released. If successful, an attacker could retrieve, alter, or delete sensitive hospital data stored in the database, compromising confidentiality and integrity of patient records.
Affected Systems
The vulnerability affects the itsourcecode Hospital Management System, specifically version 1.0. No other affected versions or subcomponents are listed. The target is the viewdepartment.php module which processes the delid parameter.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, and the flaw is not listed in CISA KEV. The description suggests that a remote attacker could trigger the vulnerability, and it is inferred that this could be accomplished by sending a crafted HTTP request to viewdepartment.php with a manipulated delid parameter. Without additional defenses, the likelihood of exploitation remains moderate to high, especially in environments where the application is exposed to the internet.
OpenCVE Enrichment