PatchSiren

onetwothreeneth CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM onetwothreeneth CVE published 2026-10-05

CVE-2026-105385

A SQL injection vulnerability was determined in onetwothreeneth HospitalManagementSystem up to version 9ef91ed6007314b6473110ed699dff76d158f61d, affecting the transaction_details.php file. The vulnerability can be exploited remotely by manipulating the transaction_id argument. This could potentially lead to unauthorized access to sensitive data. Defenders should assess exposure and prioritize verification [truncated]