Description
A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function update_subaccount of the file php/controller.php of the component Account Administration. This manipulation of the argument user_id causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized account modifications via remote exploitation
Action: Assess Impact
AI Analysis

Impact

The vulnerability is located in the update_subaccount function of the Account Administration controller, where manipulation of the user_id parameter removes proper authorization checks. An attacker who can reach the endpoint can override the target subaccount and perform unauthorized changes, leading to unauthorized modification of user data and potential privilege escalation. The weakness corresponds to incorrect privilege assignment and incorrect authorization controls.

Affected Systems

The flaw affects onetwothreeneth’s HospitalManagementSystem. All releases up to commit 9ef91ed6007314b6473110ed699dff76d158f61d are impacted. No specific version is reported due to the rolling‑release model, but any copy of the current code base before the fix contains the issue.

Risk and Exploitability

The CVSS base score is 6.9, indicating a moderate‑to‑high severity. EPSS data is not available, yet an exploit is published and listed in publicly available resources, meaning remote attackers can utilize this flaw. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can reach the web interface remotely to send crafted requests, exploiting the missing authorization checks. Because the attack is remote and the exploit exists, the risk is elevated beyond the CVSS rating.

Generated by OpenCVE AI on October 5, 2026 at 18:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the installed code against the listed commit and, if available, upgrade to the latest release that contains the fix once it is released.
  • Add strict server‑side authorization checks for the update_subaccount action, ensuring that only administrators with the necessary privileges can modify a subaccount and that the user_id parameter cannot be arbitrarily changed.
  • If a patch is not released, disable or remove the update_subaccount endpoint or restrict it to a minimal set of verified administrative users until the vulnerability is fixed. Continue monitoring vendor releases and apply any new updates promptly.

Generated by OpenCVE AI on October 5, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function update_subaccount of the file php/controller.php of the component Account Administration. This manipulation of the argument user_id causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Title onetwothreeneth HospitalManagementSystem Account Administration controller.php update_subaccount improper authorization
First Time appeared Onetwothreeneth
Onetwothreeneth hospitalmanagementsystem
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:onetwothreeneth:hospitalmanagementsystem:*:*:*:*:*:*:*:*
Vendors & Products Onetwothreeneth
Onetwothreeneth hospitalmanagementsystem
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Onetwothreeneth Hospitalmanagementsystem
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T17:55:20.202Z

Reserved: 2026-10-05T10:14:48.277Z

Link: CVE-2026-105382

cve-icon Vulnrichment

Updated: 2026-10-05T17:54:05.291Z

cve-icon NVD

Status : Received

Published: 2026-10-05T17:17:14.147

Modified: 2026-10-05T18:17:35.413

Link: CVE-2026-105382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:00:12Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization