Sceawere
Vulnerability Detail
CVE-2026-104638UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Improper Authentication in HospitalManagementSystem
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 8h ago
- Vendor
- onetwothreeneth
- Product
- HospitalManagementSystem
- Attack Type
- Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The impacted element is an unknown function of the file php/sessions.php. The manipulation of the argument ID leads to improper authentication. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T15:17:09.030Z",
"pubdate": "2026-10-02T15:17:09.030Z",
"executiveSummary": "A critical improper authentication vulnerability exists within the onetwothreeneth HospitalManagementSystem, affecting all versions up to commit hash 9ef91ed6007314b6473110ed699dff76d158f61d.\nThe vulnerability resides within the php/sessions.php file, where the manipulation of the ID argument enables unauthorized access to session management mechanisms.\nThis flaw allows remote attackers to bypass existing authentication controls, potentially granting them unauthorized access to sensitive hospital administrative or patient data.\nGiven that the vulnerability has been publicly disclosed and the project maintainers have remained unresponsive to initial reports, the risk of active exploitation is significant.\nNo specific versioning is provided due to the software's rolling release model; therefore, all current deployments should be considered high-risk.\nSuccessful exploitation requires no prior authentication, significantly lowering the barrier for entry for remote attackers.",
"technicalDetails": "The vulnerability is localized to the session handling logic implemented in php/sessions.php within the onetwothreeneth HospitalManagementSystem codebase.\nThe root cause of this security defect is the insecure implementation of authentication checks involving the ID parameter. Specifically, the application fails to adequately validate or bind the session state to the identity of the user requesting access.\nAn attacker can exploit this by crafting malicious HTTP requests that manipulate the ID argument passed to the vulnerable function within php/sessions.php. By providing an arbitrary or predictable identifier, an attacker can trick the system into associating the current request with an unauthorized session context.\nThe attack flow proceeds as follows: First, the attacker identifies that the application relies on the ID argument to maintain session state. Second, the attacker interacts with the endpoint provided by php/sessions.php, injecting a crafted value into the ID parameter. Because the application lacks robust server-side verification of session ownership or integrity, the underlying logic assumes the session token is valid and associated with an active, authenticated user.\nUpon successful manipulation, the application inadvertently grants the attacker the security context of the user associated with the manipulated ID. This bypasses the intended authentication layer, allowing the attacker to interact with the system as if they were a logged-in user with potentially elevated administrative privileges.\nThe impact of this vulnerability is severe, as it facilitates unauthorized access to the HospitalManagementSystem. Depending on the targeted session, an attacker could extract sensitive patient records, modify database entries, or perform unauthorized administrative actions.\nAs this is a remote exploitation vector, no localized access to the server environment is required. The exploit is currently public, which increases the likelihood of automated scanning and manual exploitation attempts by malicious actors targeting this specific codebase."
}