MEDIUM
onetwothreeneth
CVE published 2026-10-05
CVE-2026-105385
A SQL injection vulnerability was determined in onetwothreeneth HospitalManagementSystem up to version 9ef91ed6007314b6473110ed699dff76d158f61d, affecting the transaction_details.php file. The vulnerability can be exploited remotely by manipulating the transaction_id argument. This could potentially lead to unauthorized access to sensitive data. Defenders should assess exposure and prioritize verification [truncated]