PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105385 onetwothreeneth CVE debrief

A SQL injection vulnerability was determined in onetwothreeneth HospitalManagementSystem up to version 9ef91ed6007314b6473110ed699dff76d158f61d, affecting the transaction_details.php file. The vulnerability can be exploited remotely by manipulating the transaction_id argument. This could potentially lead to unauthorized access to sensitive data. Defenders should assess exposure and prioritize verification of the presence of this vulnerability in their inventory. The rolling release system and lack of version information for affected or updated releases require defenders to monitor for potential exploitation attempts and update the system accordingly.

Vendor
onetwothreeneth
Product
HospitalManagementSystem
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-07
Advisory published
2026-10-05
Advisory updated
2026-10-07

Who should care

Defenders responsible for onetwothreeneth HospitalManagementSystem deployments should assess exposure and prioritize verification of the presence of this vulnerability in their inventory.

Why it matters

CVE-2026-105385 is a SQL injection vulnerability in onetwothreeneth HospitalManagementSystem that can be exploited remotely, potentially leading to unauthorized access to sensitive data. Defenders should prioritize verification of the presence of this vulnerability in their inventory and implement input validation and sanitization to prevent SQL injection attacks.

  • Defenders should verify the presence of this vulnerability in their inventory and assess exposure to potential SQL injection attacks.
  • The vulnerability can be exploited remotely, potentially leading to unauthorized access to sensitive data.
  • Defenders should implement input validation and sanitization for the transaction_id argument to prevent SQL injection attacks.
  • The rolling release system and lack of version information for affected or updated releases require defenders to monitor for potential exploitation attempts and update the system accordingly.

Technical summary

A SQL injection vulnerability exists in the transaction_details.php file of onetwothreeneth HospitalManagementSystem up to version 9ef91ed6007314b6473110ed699dff76d158f61d. The vulnerability can be exploited remotely by manipulating the transaction_id argument, potentially leading to SQL injection attacks. This could result in unauthorized access to sensitive data. Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, as it can lead to SQL injection attacks. Implementing input validation and sanitization for the transaction_id argument can help prevent SQL injection attacks.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, as it can lead to SQL injection attacks.

Recommended defensive actions

  • Verify the presence of onetwothreeneth HospitalManagementSystem in your inventory and assess exposure to CVE-2026-105385.
  • Review the transaction_details.php file for potential SQL injection vulnerabilities.
  • Implement input validation and sanitization for the transaction_id argument.
  • Monitor for potential exploitation attempts and update the system according to the vendor's rolling release system.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The CVE record and source item provide details about the vulnerability, including its existence in version 9ef91ed6007314b6473110ed699dff76d158f61d of onetwothreeneth HospitalManagementSystem. However, the rolling release system and lack of version information for affected or updated releases limit the scope of the assessment.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105385 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105385

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105385 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105385

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • onetwothreeneth HospitalManagementSystem transaction_details.php sql injection

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105385.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/413579

    Supplemental source - vdb-entry, technical-description

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/413579/cti

    Supplemental source - signature, permissions-required

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/cve/CVE-2026-105385

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/submit/980279

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/onetwothreeneth/HospitalManagementSystem/issues/10

    Supplemental source - exploit, issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/onetwothreeneth/HospitalManagementSystem/

    Supplemental source - product

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.