Skip to content
Threat Feed
high advisory

SQL Injection in UNION HospitalManagementSystem

The UNION HospitalManagementSystem is vulnerable to remote SQL injection via the patient_id parameter in patient_info.php, allowing unauthenticated attackers to manipulate database queries.

CVE search metadata

CVE search record: CVE-2026-105384. Severity: high. CVSS: 7.3. KEV: no. Product: HospitalManagementSystem (up to commit 9ef91ed6007314b6473110ed699dff76d158f61d). Brief: SQL Injection in UNION HospitalManagementSystem. Brief link: https://feed.craftedsignal.io/briefs/2026-10-union-hms-sqli/

A remote SQL injection vulnerability exists in the UNION HospitalManagementSystem, specifically within the patient_info.php script. The flaw is triggered by improper sanitization of the patient_id argument, which allows an unauthenticated remote attacker to inject malicious SQL commands into the backend database. This vulnerability affects all versions of the software up to commit 9ef91ed6007314b6473110ed699dff76d158f61d. Due to the project's use of a rolling release strategy, there is no specific version identifier for a patch; users are advised to monitor the upstream repository for updates. The vulnerability has been publicly disclosed with an associated exploit, increasing the risk of exploitation for organizations utilizing this software in their environment.

Impact

Successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary SQL queries against the database supporting the HospitalManagementSystem. This could result in unauthorized access to, or exfiltration of, sensitive patient data, modification of database records, or potential bypass of authentication mechanisms. The severity is rated at 7.3 (CVSS v3.1), reflecting a high risk to the confidentiality and integrity of information stored within the system.

Recommendation

Detection engineering teams should focus on identifying unauthorized SQL injection attempts targeting the affected script. Since no formal patch is currently available, defensive measures should prioritize web application firewall (WAF) rule sets to filter input directed at the patient_info.php endpoint.

  • Implement WAF rules to inspect HTTP GET/POST requests for SQL injection patterns (e.g., UNION SELECT, sleep, database-specific metadata queries) targeting the patient_id parameter.
  • Monitor web server access logs for anomalous characters or SQL keywords in requests to /patient_info.php.
  • Review database audit logs for unauthorized access or execution of administrative commands originating from the web server's service account.

Immediate actions

Deploy WAF filtering for patient_info.php targeting patient_id parameter

SOC 24h

Mitigations

Monitor upstream repository for official patch or security release

medium_term IT Operations

CVE-2026-105384

Detection coverage 1

Detects CVE-2026-105384 Exploitation - SQL Injection in HospitalManagementSystem

high

Detects potential SQL injection attempts targeting the patient_id argument in patient_info.php.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →