CVE-2024-28320

HIGH

Mayurik Hospital Management System - IDOR

Title source: rule
STIX 2.1

Description

Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.

Scores

CVSS v3 7.6
EPSS 0.0015
EPSS Percentile 34.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
mayurik/hospital_management_system 1.0
Published Apr 29, 2024
Tracked Since Feb 18, 2026