Impact
The vulnerability exists in the viewbilling.php file of itsourcecode Hospital Management System and is triggered by manipulating the delid argument. This flaw can allow an attacker to inject arbitrary SQL commands, potentially extracting sensitive data from the database or modifying records. The impact is a compromise of data confidentiality and integrity, and it can be leveraged from a remote location.
Affected Systems
The affected product is itsourcecode Hospital Management System version 1.0. Other versions are not explicitly listed. Users running this software without an updated patch are at risk.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as medium severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting it may not yet be widely targeted by mass exploitation campaigns. However, since the attack can be launched remotely and is publicly disclosed, the potential for exploitation remains significant. An attacker can exploit the flaw by sending crafted requests to the delid parameter without needing additional privileges or system access beyond what a typical user can achieve through the web interface.
OpenCVE Enrichment