Sceawere
Vulnerability Detail
CVE-2026-104637UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unrestricted File Upload in HospitalManagementSystem
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 8h ago
- Vendor
- onetwothreeneth
- Product
- HospitalManagementSystem
- Attack Type
- Unrestricted Upload
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-02T15:17:08.830Z",
"pubdate": "2026-10-02T15:17:08.830Z",
"executiveSummary": "The onetwothreeneth HospitalManagementSystem contains a critical unrestricted file upload vulnerability within multiple functions of the php/controller.php file.\nThis vulnerability allows remote, unauthenticated or authenticated attackers to upload arbitrary files to the server, bypassing intended file type restrictions.\nBy manipulating the 'img' argument, an attacker can upload malicious scripts, such as web shells, leading to remote code execution (RCE) on the underlying host.\nThe flaw impacts multiple system controllers, including add_patient, add_physician, add_account, update_account, update_subaccount, edit_physician, and edit_patient.\nGiven that the exploit is publicly available and the project has not provided a security patch, the risk of exploitation is high. Successful exploitation results in full server compromise, potential data exfiltration, and lateral movement within the hosting environment.",
"technicalDetails": "The vulnerability originates from a lack of server-side validation and sanitization on the 'img' input parameter within the php/controller.php file. The affected functions (add_patient, add_physician, add_account, update_account, update_subaccount, edit_physician, and edit_patient) process file uploads without verifying the file extension, MIME type, or content structure, thereby facilitating an Unrestricted File Upload condition.\nThe attack flow commences when a remote attacker identifies an endpoint calling one of the vulnerable functions. The attacker crafts an HTTP request, typically a multipart/form-data POST request, substituting the intended image payload with a malicious executable file (e.g., a PHP-based web shell).\nDuring the processing phase, the controller fails to restrict the destination directory or validate the extension of the uploaded file. Consequently, the application writes the malicious payload directly into a web-accessible directory. Because the system lacks proper upload filtering, the web server executes the uploaded script when directly requested via a browser or HTTP client.\nThe vulnerability is present in versions up to the commit hash 9ef91ed6007314b6473110ed699dff76d158f61d. The exploit is currently public, significantly lowering the barrier to entry for adversaries. Once the malicious payload is successfully stored, the attacker gains the ability to execute arbitrary system commands with the privileges of the web server user (e.g., www-data).\nPost-exploitation impact includes complete takeover of the web application, access to sensitive patient data stored in the database, modification of system configurations, and potential pivot points into internal network segments. Since the system operates on a rolling release model without a formal patch management process, affected deployments remain indefinitely exposed unless manual security controls are implemented at the infrastructure level."
}