Sceawere
Vulnerability Detail
CVE-2026-104609UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in HospitalManagementSystem
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 11h ago
- Vendor
- onetwothreeneth
- Product
- HospitalManagementSystem
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function get of the file edit_accounts.php. This manipulation of the argument user_id/patient_id/physician_id/discounts_id/services_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-02T12:17:20.533Z",
"pubdate": "2026-10-02T12:17:20.533Z",
"executiveSummary": "A critical SQL injection vulnerability exists in onetwothreeneth HospitalManagementSystem up to commit 9ef91ed6007314b6473110ed699dff76d158f61d.\nThe vulnerability resides in the get function within edit_accounts.php, where multiple input parameters fail to undergo sufficient sanitization or parameterization.\nThe flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying database, potentially resulting in unauthorized data access, modification, or destruction.\nAs the exploit is publicly available, the risk of active exploitation is significant, especially given the lack of a vendor-provided patch.\nSuccessful exploitation compromises the integrity and confidentiality of sensitive patient, physician, and administrative account data.",
"technicalDetails": "The vulnerability is a classic SQL injection flaw stemming from improper neutralization of special elements used in an SQL command within edit_accounts.php.\nThe application processes user-supplied input via the get method for multiple identifiers, including user_id, patient_id, physician_id, discounts_id, and services_id.\nThe root cause is the direct concatenation of these untrusted input variables into SQL queries executed by the backend database management system without the use of prepared statements or parameterized queries.\nThe attack flow begins when an attacker sends a crafted HTTP request containing malicious SQL syntax injected into one of the identified parameters.\nBecause the application fails to validate the input data type or structure before passing it to the database driver, the database engine parses and executes the attacker's injected SQL commands alongside the intended logic.\nAn attacker can manipulate the query structure to bypass authentication mechanisms, perform unauthorized CRUD (Create, Read, Update, Delete) operations, or extract entire database tables via UNION-based, error-based, or blind SQL injection techniques.\nThe scope of impact is broad, as the vulnerability affects various critical identifiers across the system, enabling the attacker to pivot from simple information disclosure to full database administrative control, depending on the database user permissions.\nSince the project utilizes a rolling release model and the maintainers have not yet responded to the disclosed issue, no official fix exists at the commit level 9ef91ed6007314b6473110ed699dff76d158f61d, rendering systems currently deployed with this code base persistently vulnerable.\nExploitation requires no specialized authentication or high-level privileges, as the entry point in edit_accounts.php is exposed to remote manipulation."
}