在 onetwothreeneth HospitalManagementSystem 最高至版本 9ef91ed6007314b6473110ed699dff76d158f61d 中发现一个漏洞。该漏洞影响文件 php/controller.php 中的某个未知函数。对参数 transaction_idS 的恶意操控可导致 SQL 注入。此漏洞可被远程利用。相关利用代码已向公众公开,可被用于实际攻击。 该产品采用持续交付的滚动发布模式,因此受影响版本或已修复版本的具体版本信息不可用。项目方已通过问题报告尽早知悉该漏
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| onetwothreeneth | HospitalManagementSystem | 9ef91ed6007314b6473110ed699dff76d158f61d |
cpe:2.3:a:onetwothreeneth:hospitalmanagementsystem:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105382 | 7.3 HIGH | onetwothreeneth HospitalManagementSystem Account Administration controller.php update_suba |
| CVE-2026-105385 | 7.3 HIGH | onetwothreeneth HospitalManagementSystem transaction_details.php sql injection |
| CVE-2026-105386 | 7.3 HIGH | onetwothreeneth HospitalManagementSystem print.php get sql injection |
No comments yet