Executive brief
A security vulnerability exists in the itsourcecode Hospital Management System, a software platform used for managing medical records and prescriptions. An attacker with basic user access can exploit this flaw to gain unauthorized access to the underlying database. This could lead to the theft of sensitive patient information, tampering with medical records, or disruption of hospital operations.
Technical details
A SQL injection vulnerability exists in itsourcecode Hospital Management System 1.0 within the '/prescriptionorder.php' file. The root cause is a failure to properly sanitize or validate the 'editid' GET parameter before it is used in a database query. An authenticated attacker can exploit this via a time-based blind SQL injection attack (e.g., using SLEEP commands) to extract sensitive data or manipulate the database. The vulnerability can be exploited remotely, and a public proof-of-concept using sqlmap has been disclosed. Recommended remediation includes implementing prepared statements with parameter binding.
Affected products
- itsourcecode Hospital Management System 1.0
Timeline
- 2026-06-15: disclosed: Vulnerability discovered and issue opened on GitHub
- 2026-07-21: advisory: CVE published and NVD record created