CVE-2026-104637
Received Received - Intake

Unrestricted File Upload in onetwothreeneth HospitalManagementSystem

Vulnerability report for CVE-2026-104637, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulDB

Description

A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
onetwothreeneth hospitalmanagementsystem to 9ef91ed6007314b6473110ed699dff76d158f61d (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated arbitrary file upload in HospitalManagementSystem that allows Remote Code Execution (RCE) via a webshell. The issue is in the php/controller.php file where file-upload handlers write files to the web-accessible img/ directory without authentication checks, role verification, extension whitelisting, MIME validation, or filename sanitization. Attackers can upload a PHP file through forms like add_patient and execute it via a direct URL request.

Detection Guidance

Check for unauthorized PHP files in the img/ directory of the HospitalManagementSystem. Look for unexpected file uploads via the add_patient form in index.php. Review logs for direct URL requests to uploaded files. Verify if sessions.php lacks proper authentication checks.

Impact Analysis

This vulnerability allows attackers to fully compromise the system. They can read arbitrary files, dump the database including plaintext passwords, and pivot into the host system. The lack of authentication checks means anyone can exploit it remotely without credentials.

Compliance Impact

This vulnerability likely violates compliance requirements for GDPR and HIPAA due to unauthorized access to sensitive data. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A breach could lead to legal penalties and reputational damage.

Mitigation Strategies

Disable file uploads in the add_patient form. Implement authentication checks in php/sessions.php. Restrict write permissions to the img/ directory. Add MIME validation and filename sanitization for uploaded files. Monitor for unauthorized file access or execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104637. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart