Skip to content
Threat Feed
high advisory updated

SQL Injection Vulnerability in HospitalManagementSystem (CVE-2026-104609)

The onetwothreeneth HospitalManagementSystem contains a remote SQL injection vulnerability in edit_accounts.php that allows unauthenticated attackers to execute arbitrary database queries.

CVE search metadata

CVE search record: CVE-2026-104609. Severity: high. CVSS: 7.3. KEV: no. Product: HospitalManagementSystem (<= 9ef91ed6007314b6473110ed699dff76d158f61d), HospitalManagementSystem (up to commit 9ef91ed6007314b6473110ed699dff76d158f61d). Brief: SQL Injection Vulnerability in HospitalManagementSystem (CVE-2026-104609). Brief link: https://feed.craftedsignal.io/briefs/2026-10-hospital-management-sql-injection/

What's new

  • 1. added detection rule: Detect CVE-2026-105385 Exploitation - SQL Injection in HospitalManagementSystem Oct 5, 18:48 via nvd

A SQL injection vulnerability has been identified in the onetwothreeneth HospitalManagementSystem, affecting all versions up to the commit hash 9ef91ed6007314b6473110ed699dff76d158f61d. The vulnerability resides in the 'get' function within the 'edit_accounts.php' file. An attacker can remotely exploit this by manipulating the 'user_id', 'patient_id', 'physician_id', 'discounts_id', or 'services_id' arguments via crafted HTTP GET requests. Because the system follows a rolling release model, there is no specific version number to patch, and the project maintainers have not yet addressed the vulnerability despite early notification. Publicly available exploit code increases the risk of immediate exploitation against internet-facing instances of this software.

Impact

Successful exploitation of CVE-2026-104609 allows an unauthenticated, remote attacker to perform arbitrary SQL commands against the backend database. This may lead to the unauthorized disclosure, modification, or deletion of sensitive patient and administrative healthcare records. Given the nature of hospital management software, the exposure of Personally Identifiable Information (PII) and Protected Health Information (PHI) poses a significant risk to data privacy and regulatory compliance.

Recommendation

  • Implement strict input validation and parameterization on all HTTP parameters passed to 'edit_accounts.php' via a Web Application Firewall (WAF) or equivalent reverse proxy.
  • Audit database logs for anomalous queries originating from the 'edit_accounts.php' file, specifically looking for SQL syntax characters such as single quotes, double quotes, semicolons, and comment indicators within the requested ID parameters.
  • Restrict network access to the 'edit_accounts.php' endpoint to authorized internal network segments only.
  • Monitor the official project repository for future commits that introduce secure coding practices or patches addressing this vulnerability.

Immediate actions

Deploy the Sigma rule to monitor for exploitation attempts against edit_accounts.php

Detection Engineering 24h

Mitigations

Apply WAF rules to block requests containing SQL metacharacters to edit_accounts.php parameters

immediate IT Operations

CVE-2026-104609

Detection coverage 2

Detect CVE-2026-104609 Exploitation - SQL Injection in edit_accounts.php

high

Detects exploitation attempts against CVE-2026-104609 by identifying SQL injection payloads targeting edit_accounts.php parameters

sigma tactics: initial_access techniques: T1190 sources: webserver

Detect CVE-2026-105385 Exploitation - SQL Injection in HospitalManagementSystem

high

Detects potential SQL injection attempts against the transaction_details.php endpoint by looking for common SQL keywords and syntax in the transaction_id query parameter.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →