CVE-2026-105385: onetwothreeneth HospitalManagementSystem transaction_details.php sql injection
A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transactiondetails.php. Executing a manipulation of the argument transactionid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerable endpoint can be attacked remotely, and the supplied severity vector indicates no privileges or user interaction are required. Systems exposing transaction_details.php to untrusted network users are the relevant exposure.
Is there public exploit information available?
Yes. The exploit has been publicly disclosed and may be used by attackers.
Which releases are affected?
The issue is reported in HospitalManagementSystem through commit 9ef91ed6007314b6473110ed699dff76d158f61d. The project uses rolling releases and does not disclose conventional affected or fixed version numbers.
Is a vendor fix available?
The project was notified through an issue report but had not responded at the time of the report. No fixed release or patch is identified in the provided information.