This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs.
Successful exploitation of this vulnerability could allow an attacker to impersonate the target user and gain unauthorized access to user accounts on the targeted system.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs. Successful exploitation of this vulnerability could allow an attacker to impersonate the target user and gain unauthorized access to user accounts on the targeted system. | |
| Title | Sensitive Data Exposure Vulnerability in e-Sushrut HMIS | |
| First Time appeared |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| Weaknesses | CWE-319 | |
| CPEs | cpe:2.3:a:cdac-noida:e-sushrut_hospital_management_information_system_hmis_:previous_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-04-29T08:17:12.372Z
Reserved: 2026-04-28T08:14:36.620Z
Link: CVE-2026-42514
No data.
Status : Received
Published: 2026-04-29T09:16:24.553
Modified: 2026-04-29T09:16:24.553
Link: CVE-2026-42514
No data.