CVE-2026-104609
Received Received - Intake

SQL Injection in onetwothreeneth HospitalManagementSystem

Vulnerability report for CVE-2026-104609, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulDB

Description

A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function get of the file edit_accounts.php. This manipulation of the argument user_id/patient_id/physician_id/discounts_id/services_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
onetwothreeneth hospitalmanagementsystem to 9ef91ed6007314b6473110ed699dff76d158f61d (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a SQL Injection vulnerability in the HospitalManagementSystem affecting multiple edit pages (edit_accounts.php, edit_patient.php, etc.). The flaw occurs when GET parameters like user_id or patient_id are directly used in SQL queries without sanitization. Attackers can inject malicious SQL code via these parameters, such as time-based payloads like ' AND SLEEP(1)-- - to delay responses. The issue stems from raw input being embedded in SQL WHERE clauses and a lack of authentication checks on these pages.

Detection Guidance

To detect SQL injection vulnerabilities in the HospitalManagementSystem, test the affected pages (edit_accounts.php, edit_patient.php, edit_physicians.php, edit_discounts.php, edit_services.php) by injecting time-based payloads like ' AND SLEEP(1)-- - into GET parameters such as user_id, patient_id, physician_id, discounts_id, or services_id. If the response is delayed, SQL injection is likely present.

Impact Analysis

Exploitation could lead to unauthorized access and extraction of sensitive data, including patient records, financial transactions, and plaintext account passwords. Attackers could manipulate or delete data, alter records, or gain full control over the system. Since the exploit is publicly available, the risk of attacks is high.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to sensitive personal and health data. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. A breach could result in legal penalties, fines, and reputational damage for organizations using this system.

Mitigation Strategies

Immediately apply input validation and sanitization to all GET parameters used in SQL queries. Replace raw SQL queries with prepared statements or parameterized queries. Ensure authentication checks are enforced on all affected pages. Monitor network traffic for suspicious SQL injection attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104609. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart