CVE-2026-82181: Le-yan|Medical Practice Management System - Sensitive Data in URL
Published Aug 28, 2026
·Updated
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Le-yan Medical Practice Management Systemto a version that resolves this vulnerability.Fixed in 2.5.2.0
Event History
Aug 28, 2026
CVE Published
via MITRE·11:52 AM
Data Sourced
via MITRE·11:52 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need to authenticate to exploit this issue?
No. The vulnerability is described as exploitable by unauthenticated remote attackers.
2
Where can the sensitive information be exposed?
Sensitive information may be exposed through a victim's browser history or through log files when it is included in URLs.