Unprotected Prescription Page Vulnerability Could Lead to Remote Access
CVE-2024-2317
Key Information:
- Vendor
Bdtask
- Status
- Vendor
- CVE Published:
- 8 March 2024
Badges
What is CVE-2024-2317?
A security vulnerability has been identified in Bdtask Hospital AutoManager that affects the Prescription Page's ability to properly authorize user actions. Specifically, the vulnerability arises from the processing of requests to the /prescription/prescription/delete/ endpoint, which lacks adequate verification mechanisms. This may allow attackers to manipulate requests and gain unauthorized access to sensitive operations. The issue can be exploited remotely, making it crucial for users of affected versions to assess their security measures immediately. Despite prior notifications to the vendor, no response was received regarding this critical issue.
Affected Version(s)
Hospital AutoManager 20240227
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved