Executive brief
The Online Hospital Management System, a platform used for managing medical facility operations, contains a security flaw in its appointment handling component. An attacker can exploit this to gain unauthorized access to the underlying database, potentially leading to the exposure of sensitive patient records or the modification of appointment data. This could disrupt hospital operations and compromise patient privacy.
Technical details
A SQL injection vulnerability exists in code-projects Online Hospital Management System 1.0 within the 'appointmentdetail.php' file. The root cause is the improper neutralization of the 'editid' GET parameter before it is used in a database query. A remote attacker can provide crafted SQL payloads (including boolean-based, error-based, and time-based blind techniques) to manipulate queries. This allows for unauthorized database access, data extraction, and potential modification of records. While some reports suggest low privileges are required, the researcher's disclosure indicates the vulnerability may be exploitable without authentication. No official patch is currently available; users are advised to implement prepared statements and input validation.
Affected products
- code-projects Online Hospital Management System 1.0
Timeline
- 2026-05-10: disclosed: Initial researcher disclosure on GitHub
- 2026-05-31: advisory: VulDB advisory published
- 2026-06-01: advisory: NVD publication date