{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hospitalmanagementsystem-up-to-commit-9ef91ed6007314b6473110ed699dff76d158f61d/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:union:hospitalmanagementsystem:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105384"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HospitalManagementSystem (up to commit 9ef91ed6007314b6473110ed699dff76d158f61d)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sqli","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["UNION"],"content_html":"\u003cp\u003eA remote SQL injection vulnerability exists in the UNION HospitalManagementSystem, specifically within the patient_info.php script. The flaw is triggered by improper sanitization of the patient_id argument, which allows an unauthenticated remote attacker to inject malicious SQL commands into the backend database. This vulnerability affects all versions of the software up to commit 9ef91ed6007314b6473110ed699dff76d158f61d. Due to the project's use of a rolling release strategy, there is no specific version identifier for a patch; users are advised to monitor the upstream repository for updates. The vulnerability has been publicly disclosed with an associated exploit, increasing the risk of exploitation for organizations utilizing this software in their environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary SQL queries against the database supporting the HospitalManagementSystem. This could result in unauthorized access to, or exfiltration of, sensitive patient data, modification of database records, or potential bypass of authentication mechanisms. The severity is rated at 7.3 (CVSS v3.1), reflecting a high risk to the confidentiality and integrity of information stored within the system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should focus on identifying unauthorized SQL injection attempts targeting the affected script. Since no formal patch is currently available, defensive measures should prioritize web application firewall (WAF) rule sets to filter input directed at the patient_info.php endpoint.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement WAF rules to inspect HTTP GET/POST requests for SQL injection patterns (e.g., UNION SELECT, sleep, database-specific metadata queries) targeting the patient_id parameter.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous characters or SQL keywords in requests to /patient_info.php.\u003c/li\u003e\n\u003cli\u003eReview database audit logs for unauthorized access or execution of administrative commands originating from the web server's service account.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T18:48:20Z","date_published":"2026-10-05T18:48:20Z","id":"https://feed.craftedsignal.io/briefs/2026-10-union-hms-sqli/","summary":"The UNION HospitalManagementSystem is vulnerable to remote SQL injection via the patient_id parameter in patient_info.php, allowing unauthenticated attackers to manipulate database queries.","title":"SQL Injection in UNION HospitalManagementSystem","url":"https://feed.craftedsignal.io/briefs/2026-10-union-hms-sqli/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:onetwothreeneth:hospitalmanagementsystem:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-104609"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HospitalManagementSystem (\u003c= 9ef91ed6007314b6473110ed699dff76d158f61d)","HospitalManagementSystem (up to commit 9ef91ed6007314b6473110ed699dff76d158f61d)"],"_cs_severities":["high"],"_cs_tags":["web-application","sql-injection","cve-2026-104609","sqli","vulnerability"],"_cs_type":"advisory","_cs_vendors":["onetwothreeneth"],"content_html":"\u003cp\u003eA SQL injection vulnerability has been identified in the onetwothreeneth HospitalManagementSystem, affecting all versions up to the commit hash 9ef91ed6007314b6473110ed699dff76d158f61d. The vulnerability resides in the 'get' function within the 'edit_accounts.php' file. An attacker can remotely exploit this by manipulating the 'user_id', 'patient_id', 'physician_id', 'discounts_id', or 'services_id' arguments via crafted HTTP GET requests. Because the system follows a rolling release model, there is no specific version number to patch, and the project maintainers have not yet addressed the vulnerability despite early notification. Publicly available exploit code increases the risk of immediate exploitation against internet-facing instances of this software.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-104609 allows an unauthenticated, remote attacker to perform arbitrary SQL commands against the backend database. This may lead to the unauthorized disclosure, modification, or deletion of sensitive patient and administrative healthcare records. Given the nature of hospital management software, the exposure of Personally Identifiable Information (PII) and Protected Health Information (PHI) poses a significant risk to data privacy and regulatory compliance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict input validation and parameterization on all HTTP parameters passed to 'edit_accounts.php' via a Web Application Firewall (WAF) or equivalent reverse proxy.\u003c/li\u003e\n\u003cli\u003eAudit database logs for anomalous queries originating from the 'edit_accounts.php' file, specifically looking for SQL syntax characters such as single quotes, double quotes, semicolons, and comment indicators within the requested ID parameters.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the 'edit_accounts.php' endpoint to authorized internal network segments only.\u003c/li\u003e\n\u003cli\u003eMonitor the official project repository for future commits that introduce secure coding practices or patches addressing this vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T18:48:30Z","date_published":"2026-10-02T14:25:05Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hospital-management-sql-injection/","summary":"The onetwothreeneth HospitalManagementSystem contains a remote SQL injection vulnerability in edit_accounts.php that allows unauthenticated attackers to execute arbitrary database queries.","title":"SQL Injection Vulnerability in HospitalManagementSystem (CVE-2026-104609)","url":"https://feed.craftedsignal.io/briefs/2026-10-hospital-management-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - HospitalManagementSystem (Up to Commit 9ef91ed6007314b6473110ed699dff76d158f61d)","version":"https://jsonfeed.org/version/1.1"}