Executive brief
itsourcecode Hospital Management System is a web application used for managing medical facility operations. A security vulnerability in the password change feature allows logged-in users to execute unauthorized database commands. This could lead to the theft of sensitive patient data, unauthorized modification of medical records, or disruption of hospital services.
Technical details
A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 within the '/patientchangepassword.php' file. The root cause is the improper neutralization of special elements in the 'newpassword' POST parameter. An attacker with valid patient credentials can exploit this via a time-based blind SQL injection attack to manipulate backend database queries. Successful exploitation can lead to unauthorized database access, data leakage, and potential system control. A public proof-of-concept (PoC) using sqlmap has been disclosed. No official patch is currently documented, but remediation should involve implementing prepared statements and input validation.
Affected products
- itsourcecode Hospital Management System 1.0
Timeline
- 2026-05-31: disclosed: Initial vulnerability report on GitHub
- 2026-06-29: advisory: NVD publication date