Sceawere

Vulnerability Detail

CVE-2026-105383UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in HospitalManagementSystem

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
2h ago
Vendor
onetwothreeneth
Product
HospitalManagementSystem
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This impacts an unknown function of the file php/controller.php. Such manipulation of the argument transaction_idS leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T17:17:14.327Z",
  "pubdate": "2026-10-05T17:17:14.327Z",
  "executiveSummary": "The onetwothreeneth HospitalManagementSystem contains a critical SQL injection vulnerability within the php/controller.php file.\nThis flaw allows remote, unauthenticated attackers to manipulate database queries by injecting malicious SQL statements through the transaction_idS parameter.\nSuccessful exploitation enables unauthorized parties to bypass authentication, access sensitive medical records, modify database content, or potentially gain full control over the underlying database server.\nThe vulnerability affects all versions up to commit 9ef91ed6007314b6473110ed699dff76d158f61d.\nGiven that the project uses a rolling release model and the maintainers have not yet responded to disclosure, the system remains in a high-risk state with public exploit information available.\nOrganizations relying on this software should implement immediate defensive measures at the network or application layer, as no official vendor patch is currently available.",
  "technicalDetails": "The vulnerability resides within the php/controller.php script of the HospitalManagementSystem, specifically stemming from improper input validation and sanitization of the 'transaction_idS' HTTP request argument.\nThe root cause is the direct concatenation of user-supplied input from the transaction_idS parameter into dynamic SQL query strings before being executed by the database management system. Because the application fails to utilize prepared statements, parameterized queries, or robust input filtering, the input is treated as executable code rather than literal data.\nAn attacker can exploit this remotely by crafting a malicious HTTP request that includes specially formatted SQL syntax within the transaction_idS parameter. By injecting characters such as single quotes, semicolons, or comments, the attacker can manipulate the structure of the intended SQL command.\nThe attack flow proceeds as follows: First, the attacker identifies the vulnerable endpoint at php/controller.php. Second, the attacker submits a crafted payload via the transaction_idS argument, which might look like '123' OR '1'='1' or more sophisticated UNION-based injections to extract information from database tables.\nOnce the payload is submitted, the database interpreter processes the modified query string, executing the injected commands. This interaction occurs without requiring any prior authentication or specific privileges, significantly lowering the barrier to entry for potential adversaries.\nThe post-exploitation impact is severe. Since the application likely runs with elevated database permissions, an attacker can perform unauthorized data exfiltration, dump sensitive patient health information (PHI), or overwrite existing data. In environments where database features allow for file system interaction or command execution—such as 'INTO OUTFILE' or 'xp_cmdshell'—the vulnerability could be leveraged to gain remote code execution (RCE) on the database server itself, leading to a full system compromise.\nThe lack of vendor intervention implies that the flaw remains persistent in all existing deployments up to the affected commit hash. Defensive isolation is currently the only viable strategy until the underlying codebase is updated to implement safe database interaction patterns."
}
CVE-2026-105383: SQL Injection in HospitalManagementSystem (HIGH Severity, CVSS: 7.3) | Sceawere