This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated attacker could exploit this vulnerability by manipulating encoded parameters in the request URL to gain unauthorized access to patient accounts on the targeted system.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Apr 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated attacker could exploit this vulnerability by manipulating encoded parameters in the request URL to gain unauthorized access to patient accounts on the targeted system. | |
| Title | Broken Access Control Vulnerability in e-Sushrut HMIS | |
| First Time appeared |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:cdac-noida:e-sushrut_hospital_management_information_system_hmis_:previous_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-04-29T08:26:15.611Z
Reserved: 2026-04-28T08:14:36.620Z
Link: CVE-2026-42516
No data.
Status : Received
Published: 2026-04-29T09:16:24.803
Modified: 2026-04-29T09:16:24.803
Link: CVE-2026-42516
No data.