在 onetwothreeneth HospitalManagementSystem(最高至提交版本 9ef91ed6007314b6473110ed699dff76d158f61d)中发现了一个漏洞。受此问题影响的是 print.php 文件中的 get 方法。对参数 transaction_id 的操纵可导致 SQL 注入。该漏洞可被远程发起攻击。相关利用代码已公开,可能被他人使用。该产品采用滚动发布模式以支持持续交付,因此无法提供受影响版本及修复后更新版本的具体版本号。该项目方已通过问题报告在早期获悉此漏洞,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| onetwothreeneth | HospitalManagementSystem | 9ef91ed6007314b6473110ed699dff76d158f61d |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| onetwothreeneth | HospitalManagementSystem | 9ef91ed6007314b6473110ed699dff76d158f61d |
cpe:2.3:a:onetwothreeneth:hospitalmanagementsystem:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105382 | 7.3 HIGH | onetwothreeneth HospitalManagementSystem Account Administration controller.php update_suba |
| CVE-2026-105383 | 7.3 HIGH | onetwothreeneth HospitalManagementSystem controller.php sql injection |
| CVE-2026-105385 | 7.3 HIGH | onetwothreeneth HospitalManagementSystem transaction_details.php sql injection |
No comments yet