Executive brief
A security vulnerability exists in the itsourcecode Hospital Management System, a software platform used by healthcare facilities to manage patient records and prescriptions. An attacker with basic user credentials can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the theft of sensitive patient information, unauthorized modification of medical records, or disruption of hospital operations.
Technical details
A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 within the /prescriptionrecord.php file. The root cause is the improper sanitization of the 'delid' GET/POST parameter before its use in a database query. An authenticated attacker with low-level privileges can provide malicious SQL commands through this parameter to bypass security controls. Successful exploitation allows for unauthorized data retrieval, modification, or deletion from the database. A public proof-of-concept (PoC) demonstrating a time-based blind SQL injection (using SLEEP) has been disclosed.
Affected products
- itsourcecode Hospital Management System 1.0
Timeline
- 2026-06-12: disclosed: Initial vulnerability report on GitHub
- 2026-07-18: advisory: NVD/VulDB publication date