Sceawere

Vulnerability Detail

CVE-2026-105384UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in UNION HospitalManagementSystem

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
UNION
Product
HospitalManagementSystem
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in UNION HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected is an unknown function of the file patient_info.php. Performing a manipulation of the argument patient_id results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T18:17:35.553Z",
  "pubdate": "2026-10-05T18:17:35.553Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the UNION HospitalManagementSystem, specifically within the patient_info.php file.\nThis vulnerability allows an unauthenticated or authenticated remote attacker to manipulate the 'patient_id' argument, leading to unauthorized execution of arbitrary SQL commands against the backend database.\nThe flaw stems from insufficient input validation and sanitization of user-supplied data before it is incorporated into database queries.\nThe risk implication is severe, as successful exploitation could lead to unauthorized data exfiltration, modification, or deletion of sensitive patient information stored within the hospital management system.\nSince the product utilizes a rolling release model, all installations prior to commit 9ef91ed6007314b6473110ed699dff76d158f61d are considered vulnerable.\nPublicly available exploit code increases the risk of active exploitation by malicious actors.\nThe vulnerability is currently unpatched, leaving exposed systems at risk of compromise.",
  "technicalDetails": "The vulnerability resides within the 'patient_info.php' script of the UNION HospitalManagementSystem. The root cause is the improper handling of the 'patient_id' HTTP GET or POST parameter, which is directly concatenated into a SQL query string without adequate sanitization, parameterization, or the use of prepared statements.\nThe attack flow commences when an attacker identifies the 'patient_id' parameter as an injection vector. By supplying crafted malicious SQL payloads, an attacker can manipulate the query's structure, effectively altering the logic of the SQL statement intended for the database backend. For example, if the query is constructed as SELECT * FROM patients WHERE id = ' + $_GET['patient_id'], an attacker can inject ' OR 1=1-- to bypass authentication checks or retrieve unauthorized patient records.\nExploitation is feasible remotely over the network, as the interface is exposed to external requests. The vulnerability does not appear to require specialized authentication or elevated privileges, potentially allowing an anonymous attacker to interact with the database directly. The payload behavior is limited only by the privileges assigned to the database user account used by the application, potentially permitting full database enumeration, data dump, or even database server control in cases of excessive privileges.\nThe impact of a successful attack is extensive. Beyond the immediate threat of sensitive PHI (Protected Health Information) exposure—which violates data privacy regulations—the attacker may perform blind SQL injection to infer database structures, version details, and administrative credentials. If the database user has sufficient privileges, the attacker could also perform data manipulation, such as deleting records, modifying patient data, or escalating privileges within the application if the authentication database is accessible. Given that the project has not responded to reported issues, no official patch exists, and the exploitability remains high for any instance running the identified commit or earlier versions."
}
CVE-2026-105384: SQL Injection in UNION HospitalManagementSystem (HIGH Severity, CVSS: 7.3) | Sceawere