First published: Mon Apr 29 2024(Updated: )
Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hospital Management System | ||
Mayurik Free Hospital Management System For Small Practices | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28320 is considered a high severity vulnerability due to its potential for unauthorized access and data modification.
To fix CVE-2024-28320, implement proper authentication and access controls to validate user permissions before allowing access to sensitive user parameters.
Attackers can exploit CVE-2024-28320 to perform unauthorized account access and modifications by manipulating parameters in crafted POST requests.
CVE-2024-28320 affects version 1.0 of the Hospital Management System.
Yes, CVE-2024-28320 can be easily exploited by attackers with basic knowledge of crafting HTTP requests.