Impact
A vulnerability exists in itsourcecode Hospital Management System, specifically in the viewappointmentpending.php module. Manipulation of the 'delid' argument allows an attacker to inject arbitrary SQL statements. This flaw is classified as a classic SQL injection (CWE-74, CWE-89) and can be exploited remotely, potentially enabling an attacker to read, modify, or delete appointment records and other sensitive data stored in the database.
Affected Systems
The affected product is itsourcecode Hospital Management System version 1.0. The vulnerability resides in the unknown portion of the file /viewappointmentpending.php within this product. No other vendors or product variants are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium level of severity. Because the attack vector is remote and the exploit is publicly available, the risk to systems still running the vulnerable version is significant. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so there is no current indication of widespread active exploitation, but the potential impact remains substantial for organizations that rely on this system.
OpenCVE Enrichment