PatchSiren cyber security CVE debrief
CVE-2026-105385 onetwothreeneth CVE debrief
A SQL injection vulnerability was determined in onetwothreeneth HospitalManagementSystem up to version 9ef91ed6007314b6473110ed699dff76d158f61d, affecting the transaction_details.php file. The vulnerability can be exploited remotely by manipulating the transaction_id argument. This could potentially lead to unauthorized access to sensitive data. Defenders should assess exposure and prioritize verification of the presence of this vulnerability in their inventory. The rolling release system and lack of version information for affected or updated releases require defenders to monitor for potential exploitation attempts and update the system accordingly.
- Vendor
- onetwothreeneth
- Product
- HospitalManagementSystem
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for onetwothreeneth HospitalManagementSystem deployments should assess exposure and prioritize verification of the presence of this vulnerability in their inventory.
Why it matters
CVE-2026-105385 is a SQL injection vulnerability in onetwothreeneth HospitalManagementSystem that can be exploited remotely, potentially leading to unauthorized access to sensitive data. Defenders should prioritize verification of the presence of this vulnerability in their inventory and implement input validation and sanitization to prevent SQL injection attacks.
- Defenders should verify the presence of this vulnerability in their inventory and assess exposure to potential SQL injection attacks.
- The vulnerability can be exploited remotely, potentially leading to unauthorized access to sensitive data.
- Defenders should implement input validation and sanitization for the transaction_id argument to prevent SQL injection attacks.
- The rolling release system and lack of version information for affected or updated releases require defenders to monitor for potential exploitation attempts and update the system accordingly.
Technical summary
A SQL injection vulnerability exists in the transaction_details.php file of onetwothreeneth HospitalManagementSystem up to version 9ef91ed6007314b6473110ed699dff76d158f61d. The vulnerability can be exploited remotely by manipulating the transaction_id argument, potentially leading to SQL injection attacks. This could result in unauthorized access to sensitive data. Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, as it can lead to SQL injection attacks. Implementing input validation and sanitization for the transaction_id argument can help prevent SQL injection attacks.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, as it can lead to SQL injection attacks.
Recommended defensive actions
- Verify the presence of onetwothreeneth HospitalManagementSystem in your inventory and assess exposure to CVE-2026-105385.
- Review the transaction_details.php file for potential SQL injection vulnerabilities.
- Implement input validation and sanitization for the transaction_id argument.
- Monitor for potential exploitation attempts and update the system according to the vendor's rolling release system.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE record and source item provide details about the vulnerability, including its existence in version 9ef91ed6007314b6473110ed699dff76d158f61d of onetwothreeneth HospitalManagementSystem. However, the rolling release system and lack of version information for affected or updated releases limit the scope of the assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105385 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105385
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105385 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105385
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
onetwothreeneth HospitalManagementSystem transaction_details.php sql injection
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105385.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413579
Supplemental source - vdb-entry, technical-description
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413579/cti
Supplemental source - signature, permissions-required
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105385
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/980279
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/onetwothreeneth/HospitalManagementSystem/issues/10
Supplemental source - exploit, issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/onetwothreeneth/HospitalManagementSystem/
Supplemental source - product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.