This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vulnerability by intercepting and modifying the server response.
Successful exploitation of this vulnerability could allow the attacker to bypass authentication and gain unauthorized access to user accounts on the targeted system.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Apr 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cdac-noida e-sushrut Hmis
|
|
| Vendors & Products |
Cdac-noida e-sushrut Hmis
|
Wed, 29 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 |
Wed, 29 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vulnerability by intercepting and modifying the server response. Successful exploitation of this vulnerability could allow the attacker to bypass authentication and gain unauthorized access to user accounts on the targeted system. | |
| Title | Authentication Bypass Vulnerability in e-Sushrut HMIS | |
| First Time appeared |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| CPEs | cpe:2.3:a:cdac-noida:e-sushrut_hospital_management_information_system_hmis_:previous_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-04-29T08:13:23.151Z
Reserved: 2026-04-28T08:14:36.620Z
Link: CVE-2026-42513
No data.
Status : Received
Published: 2026-04-29T09:16:24.417
Modified: 2026-04-29T09:16:24.417
Link: CVE-2026-42513
No data.