Sceawere
Vulnerability Detail
CVE-2026-105385UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in HospitalManagementSystem
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 3h ago
- Vendor
- onetwothreeneth
- Product
- HospitalManagementSystem
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transaction_details.php. Executing a manipulation of the argument transaction_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T18:17:35.740Z",
"pubdate": "2026-10-05T18:17:35.740Z",
"executiveSummary": "The onetwothreeneth HospitalManagementSystem contains a critical SQL injection vulnerability within the transaction_details.php component.\nThis flaw arises from improper neutralization of input data supplied through the transaction_id argument.\nThe vulnerability allows remote, unauthenticated attackers to execute arbitrary SQL commands against the backend database, potentially resulting in unauthorized data exfiltration, modification, or deletion.\nGiven that the application utilizes a rolling release model, the vulnerability persists across all versions up to commit 9ef91ed6007314b6473110ed699dff76d158f61d.\nThe exposure of sensitive healthcare-related transaction data poses significant privacy and integrity risks.\nAs the exploit is publicly disclosed, the system is susceptible to automated and manual exploitation attempts by malicious actors.",
"technicalDetails": "The vulnerability originates in the transaction_details.php script, which serves as an interface for querying or displaying transaction records. The root cause is the insufficient sanitization of the transaction_id HTTP request parameter before it is concatenated into a database query string.\nWhen an attacker provides a maliciously crafted string containing SQL syntax to the transaction_id argument, the application fails to distinguish between legitimate user-supplied data and executable database instructions. This allows an attacker to break out of the intended query structure, facilitating SQL injection.\nThe attack flow begins with the attacker identifying the entry point at transaction_details.php. By manipulating the transaction_id parameter, the attacker can append UNION-based queries, boolean-based inference techniques, or time-based blind SQL injection payloads. This enables the attacker to probe the database structure, enumerate table names, and extract sensitive information from the underlying database management system.\nBecause the vulnerability occurs at the application layer, it can be exploited remotely over the network without the requirement for prior authentication. The execution of arbitrary SQL commands provides the attacker with a high degree of control over the database, allowing for unauthorized access to medical records, financial data, and system configurations.\nThe absence of parameterized queries or prepared statements in the affected code path allows the injected SQL to be parsed and executed by the database engine. This bypasses typical access control measures enforced by the application logic, as the queries run with the privileges of the database user account connected to the HospitalManagementSystem.\nPost-exploitation impact includes full data breach potential, where an attacker can dump entire databases, modify transactional records to hide malicious activity, or leverage database-specific features to perform administrative actions if the database service is misconfigured. Due to the rolling release nature of the software, users must treat all current instances as vulnerable until the upstream source code is updated and audited to enforce strict input validation or the implementation of prepared statements."
}