Executive brief
A vulnerability has been identified in the SourceCodester Hospitals Patient Records Management System, a web application used for managing medical patient data. An attacker can exploit this flaw to gain unauthorized access to the underlying database without needing a username or password. This could lead to the theft of sensitive patient records, unauthorized modification of medical history, or a complete disruption of the system's operations.
Technical details
A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System 1.0 within the '/classes/Master.php' file. The 'save_patient_history' function fails to properly sanitize or validate the 'id' parameter before using it in a database query. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request containing malicious SQL commands. Successful exploitation allows for unauthorized database access, data exfiltration, and potential system compromise. A public exploit (PoC) using boolean-based blind SQL injection has been disclosed.
Affected products
- SourceCodester Hospitals Patient Records Management System 1.0
Timeline
- 2026-04-25: disclosed: Vulnerability reported on GitHub by user zzb1388
- 2026-05-24: advisory: CVE published by VulDB/NVD