在 onetwothreeneth HospitalManagementSystem(版本直至 commit hash 9ef91ed6007314b6473110ed699dff76d158f61d)中发现了一个漏洞。该漏洞影响文件 transaction_details.php 中的一个未知功能。通过对参数 transaction_id 进行操纵,可导致 SQL 注入漏洞。此攻击可从远程执行。该漏洞的利用方法已公开披露,且可被利用。该产品采用持续交付的滚动发布机制,因此受影响或已修复版本的具体版本信息不予公开。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| onetwothreeneth | HospitalManagementSystem | 9ef91ed6007314b6473110ed699dff76d158f61d |
cpe:2.3:a:onetwothreeneth:hospitalmanagementsystem:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105382 | 7.3 HIGH | onetwothreeneth HospitalManagementSystem Account Administration controller.php update_suba |
| CVE-2026-105383 | 7.3 HIGH | onetwothreeneth HospitalManagementSystem controller.php sql injection |
| CVE-2026-105386 | 7.3 HIGH | onetwothreeneth HospitalManagementSystem print.php get sql injection |
No comments yet