CVE-2026-105385: onetwothreeneth HospitalManagementSystem transaction_details.php sql injection

Published Oct 5, 2026
·
Updated

A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transactiondetails.php. Executing a manipulation of the argument transactionid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

1 affected component
onetwothreeneth HospitalManagementSystem<=9ef91ed6007314b6473110ed699dff76d158f61d

Event History

Oct 5, 2026
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

The vulnerable endpoint can be attacked remotely, and the supplied severity vector indicates no privileges or user interaction are required. Systems exposing transaction_details.php to untrusted network users are the relevant exposure.

2

Is there public exploit information available?

Yes. The exploit has been publicly disclosed and may be used by attackers.

3

Which releases are affected?

The issue is reported in HospitalManagementSystem through commit 9ef91ed6007314b6473110ed699dff76d158f61d. The project uses rolling releases and does not disclose conventional affected or fixed version numbers.

4

Is a vendor fix available?

The project was notified through an issue report but had not responded at the time of the report. No fixed release or patch is identified in the provided information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203