Description
A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unrestricted File Upload leading to potential remote code execution
Action: Assess Impact
AI Analysis

Impact

The HospitalManagementSystem accepts an "img" parameter in several controller functions and allows an attacker to supply arbitrary files without validating the file type or content. This flaw enables unrestricted upload of any file, including executable code. If an attacker uploads a malicious script to a web‑accessible location, it could be executed with the web server’s privileges, resulting in full compromise of the host. The weakness is characterized by CWE‑284 (Improper Access Control) and CWE‑434 (Unrestricted Upload of File with Dangerous Type).

Affected Systems

Onetwothreeneth’s HospitalManagementSystem is affected. The project follows a rolling release model and no specific versions are identified as fixed or vulnerable; the vulnerability exists in any release up to the commit 9ef91ed6007314b6473110ed699dff76d158f61d.

Risk and Exploitability

The CVSS score is 6.9 and the EPSS score is not available, indicating a moderate severity with uncertain exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the public disclosure of an exploit and the statement that the attack may be launched remotely, the likely attack vector is a remote HTTP request that includes a crafted "img" value. An attacker could therefore achieve execution of arbitrary code on the affected system.

Generated by OpenCVE AI on October 2, 2026 at 16:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a patched version of HospitalManagementSystem as soon as it is released by onetwothreeneth
  • Modify the controller to accept only whitelisted image extensions and verify MIME types before saving the file
  • Change the permissions of the upload directory to deny execution and, if possible, store uploads outside the web root

Generated by OpenCVE AI on October 2, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Title onetwothreeneth HospitalManagementSystem controller.php edit_patient unrestricted upload
First Time appeared Onetwothreeneth
Onetwothreeneth hospitalmanagementsystem
Weaknesses CWE-284
CWE-434
CPEs cpe:2.3:a:onetwothreeneth:hospitalmanagementsystem:*:*:*:*:*:*:*:*
Vendors & Products Onetwothreeneth
Onetwothreeneth hospitalmanagementsystem
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Onetwothreeneth Hospitalmanagementsystem
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-02T15:05:20.597Z

Reserved: 2026-10-02T04:24:03.634Z

Link: CVE-2026-104637

cve-icon Vulnrichment

Updated: 2026-10-02T15:05:16.601Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T15:17:08.830

Modified: 2026-10-02T17:52:32.600

Link: CVE-2026-104637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:15:07Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-434

    Unrestricted Upload of File with Dangerous Type