Executive brief
itsourcecode Hospital Management System is a PHP-based web application for managing hospital operations including appointment scheduling. A SQL injection vulnerability in the appointment viewing functionality allows authenticated attackers to inject malicious SQL commands through the delid parameter, potentially exposing, modifying, or deleting sensitive patient data or gaining unauthorized system access.
Technical details
The vulnerability is a SQL injection flaw in the /viewappointmentpending.php file where the delid parameter is not properly sanitized before being incorporated into SQL queries. An attacker with valid login credentials can craft malicious SQL payloads (such as time-based blind SQL injection using SLEEP functions) to manipulate database queries. The attack is remotely exploitable via HTTP GET requests and requires valid authentication. A successful exploit allows an attacker to read, modify, or delete database records, potentially compromising patient data confidentiality, integrity, and system availability. The recommended fix is to implement prepared statements with parameter binding and enforce strict input validation.
Affected products
- itsourcecode Hospital Management System 1.0
Timeline
- 2026-07-05: disclosed
- 2026-08-20: advisory