Impact
A flaw in the itsourcecode Hospital Management System 1.0 allows an attacker to manipulate the delid parameter on the /viewappointmentapproved.php page, causing arbitrary SQL code to be executed against the database. The vulnerability is an example of a classic SQL injection weakness and could let a remote actor execute commands within the context of the application’s database account.
Affected Systems
The affected product is the itsourcecode Hospital Management System version 1.0. No other versions or components are listed in the advisory.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. However, the exploit has been made public, and remote exploitation via a web interface is possible, implying that attackers could trigger the injection by supplying a crafted delid value.
OpenCVE Enrichment