CVE-2026-105382 | onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d Account Administration php/controller.php update_subaccount user_id improper authorization
A vulnerability, which was classified as critical, has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function update_subaccount of the file php/controller.php of the component Account Administration. This manipulation of the argument user_id causes improper authorization.
This vulnerability is registered as CVE-2026-105382. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More