Unprotected Prescription Page Vulnerability Could Lead to Remote Access
CVE-2024-2317

9.1CRITICAL

Key Information:

Vendor

Bdtask

Vendor
CVE Published:
8 March 2024

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2024-2317?

A security vulnerability has been identified in Bdtask Hospital AutoManager that affects the Prescription Page's ability to properly authorize user actions. Specifically, the vulnerability arises from the processing of requests to the /prescription/prescription/delete/ endpoint, which lacks adequate verification mechanisms. This may allow attackers to manipulate requests and gain unauthorized access to sensitive operations. The issue can be exploited remotely, making it crucial for users of affected versions to assess their security measures immediately. Despite prior notifications to the vendor, no response was received regarding this critical issue.

Affected Version(s)

Hospital AutoManager 20240227

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

srivishnu (VulDB User)
.