Executive brief
The kishan0725 Hospital Management System, a software platform used for managing medical facility operations, contains a security flaw that could allow unauthorized access to its database. By exploiting this vulnerability in the email availability check feature, an attacker could potentially view, modify, or delete sensitive patient records and administrative data. This poses a significant risk to patient privacy and the overall integrity of the hospital's digital operations.
Technical details
A SQL injection vulnerability exists in kishan0725 Hospital Management System 4.0 within the 'check_availability.php' component. The application fails to properly sanitize user-supplied input provided through the 'emailid' and 'email' parameters before using it in a database query. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the vulnerable endpoint. Successful exploitation allows the attacker to execute arbitrary SQL commands, potentially leading to full database compromise, including the extraction of sensitive information or unauthorized administrative access. The vulnerability was identified via TaintRadar analysis.
Affected products
- kishan0725 Hospital Management System 4.0
Timeline
- 2026-07-29: disclosed: Initial NVD publication date
References
- https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-check_availability.php-email-sqli/20250811-hospital-management-system-check_availability.php-email-sqli.md
- https://github.com/um-dsp/TaintRadar/blob/main/sql_injection_cves/hospitalmanagementsystemproject/20250811-hospital-management-system-check_availability.php-emailid-sqli/20250811-hospital-management-system-check_availability.php-emailid-sqli.md