Sceawere
Vulnerability Detail
CVE-2026-105386UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HospitalManagementSystem SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 2h ago
- Vendor
- onetwothreeneth
- Product
- HospitalManagementSystem
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T19:17:16.700Z",
"pubdate": "2026-10-05T19:17:16.700Z",
"executiveSummary": "A critical input validation vulnerability has been identified within the onetwothreeneth HospitalManagementSystem, specifically affecting all deployments up to the repository commit state 9ef91ed6007314b6473110ed699dff76d158f61d. This vulnerability is classified as a SQL injection (SQLi) and resides within the get function of the print.php source file. Due to the project's utilization of a rolling release model designed for continuous delivery, standard version numbers are unavailable, meaning any instance running code up to the specified commit is vulnerable.\nThe impact of this security flaw is severe, as it permits remote, unauthenticated attackers to execute arbitrary SQL commands against the backend database. This capability allows unauthorized actors to bypass standard authentication mechanisms, access highly sensitive patient and administrative records, alter database schema and contents, or potentially escalate privileges depending on the database configuration. Given that public exploit code is actively available, the likelihood of exploitation is high. Organizations utilizing this hospital management platform are urged to implement immediate mitigations and review system logs for indicators of compromise.",
"technicalDetails": "The root cause of this vulnerability lies in the unsafe construction of SQL queries within the get function located in print.php. Specifically, the application extracts the transaction_id parameter from incoming HTTP requests and concatenates it directly into a SQL query string without utilizing parameterized queries or sanitization mechanisms. This programmatic oversight allows the database engine to interpret user-supplied input as executable SQL commands rather than inert data.\nThe exploitation process begins when a remote attacker identifies the endpoint associated with print.php and targets the transaction_id parameter. By sending a crafted HTTP request, the attacker supplies a payload designed to manipulate the query structure. For example, an attacker can append SQL syntax such as UNION operators or boolean logic statements. When the print.php script invokes the get function, the application passes this malformed string to the database interpreter. The database then processes the payload, executing the injected commands.\nThis allows the attacker to perform arbitrary SELECT queries, extracting sensitive database elements including administrative credentials, user records, and application metadata. Furthermore, if the database server configuration allows stacked queries or external file access, the attacker might escalate the attack to perform data modification, system file read/write operations, or potentially achieve remote code execution on the hosting server.\nTo execute the exploit, the attacker does not require any prior authentication or local network access, making it highly exploitable over the public internet if the system is exposed. The network exposure is broad, as the print.php script is accessible via standard web ports (HTTP/HTTPS). During post-exploitation, the threat actor can leverage the SQL injection vulnerability to completely map the relational database structure, dump the contents of all database tables, and potentially write arbitrary files to the web root if the database user has sufficient privileges. This can lead to the deployment of web shells, establishing persistent backdoor access to the underlying operating system."
}