Impact
A flaw in the doctorlogin.php component of the online clinic management system allows remote manipulation of the doc_mail and doc_pswd parameters to inject arbitrary SQL statements. This vulnerability, classified as CWE-74 and CWE-89, can lead to compromise of sensitive data stored in the underlying database and may allow attackers to alter or delete records. The impact is primarily the confidentiality and integrity of patient and administrative information.
Affected Systems
The affected product is subhajitkhan:online-clinic-management-system, specifically up to the commit e9ee77a8827a1446220fa07ee693dc4d9a29a578. The system follows a rolling release model, so no explicit version numbers are available for the vulnerable state.
Risk and Exploitability
The CVSS severity score of 6.9 indicates a medium to high risk. The EPSS score is not available, and the vulnerability is not yet listed in CISA KEV. Publication of an exploit and the ability to trigger the flaw remotely suggest a realistic threat. Because the attack vector is remote via standard web requests, any exposed instance of the application is susceptible until mitigated.
OpenCVE Enrichment