CVE-2026-105384: UNION HospitalManagementSystem patient_info.php sql injection
A vulnerability was found in UNION HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected is an unknown function of the file patientinfo.php. Performing a manipulation of the argument patientid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an authenticated account or local access?
No privileges or user interaction are required according to the CVSS vector. The issue is remotely exploitable through the patient_id argument handled by patient_info.php.
How can I determine whether my deployment is affected?
Check whether your deployed source includes patient_info.php and compare its revision with commit 9ef91ed6007314b6473110ed699dff76d158f61d or an earlier affected revision. Release-version identification is not available because the project uses a rolling release model.
Is a fix or vendor response available?
No specific fixed release is identified. The project was notified through an issue report but had not responded at the time of publication.