Impact
The vulnerability occurs in the generate_index_pasien method of the HospitalManagement application, allowing an attacker to manipulate the cari argument. This manipulation can result in a SQL injection, enabling execution of arbitrary SQL statements against the database. Consequently, the attacker could read, modify or delete sensitive patient data, compromising confidentiality, integrity, and potentially availability by disrupting database operations.
Affected Systems
The affected vendor is gedelumbung, specifically the HospitalManagement application. The bug exists in all releases up to commit c2d45543789a3887067d3915f69d44cfc2cf76a8. No specific release numbers are available due to the project's rolling release model.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can reach the vulnerable code remotely, and a publicly disclosed exploit is available. Because the flaw allows arbitrary SQL execution, the potential impact can be substantial if an attacker accesses sensitive data or disrupts database availability.
OpenCVE Enrichment