Impact
The flaw lies in the /viewservicetype.php file of itsourcecode Hospital Management System Project in PHP 1.0, where the delid argument is inadequately sanitized, enabling an attacker to inject arbitrary SQL statements. This vulnerability is classified as CWE-74 and CWE-89. When exploited, an attacker can read, modify, or delete database records, thereby compromising the integrity and confidentiality of patient or hospital data, though it does not directly grant arbitrary code execution.
Affected Systems
The affected product is the itsourcecode Hospital Management System Project in PHP, version 1.0. No specific sub‑product or module list is supplied beyond the file viewservicetype.php, and the impact applies to installations that expose this endpoint without further access controls.
Risk and Exploitability
The CVSS base score is 5.3, indicating a moderate severity. EPSS data is not available, and the vulnerability has not been recorded in the CISA KEV catalog. The attack vector is remote, as the flaw can be triggered by crafted HTTP requests to the vulnerable script, and an exploit has already been published, meaning there is an existing proof‑of‑concept. Even without EPSS, the combination of remote accessibility and published exploitation code raises the likelihood of real‑world attacks.
OpenCVE Enrichment