Cross-Site Request Forgery Vulnerability in kishan0725's Hospital Management System
CVE-2024-45983

6.3MEDIUM

Key Information:

Vendor

kishan0725

Vendor
CVE Published:
26 September 2024

What is CVE-2024-45983?

A Cross-Site Request Forgery (CSRF) vulnerability found in version 6.3.5 of kishan0725's Hospital Management System enables attackers to exploit the system by crafting a malicious HTML form. This form prompts authenticated admin users to unintentionally submit requests that can delete sensitive doctor records. By tricking the admin into visiting a specially designed web page, attackers can leverage the admin's browser session, making unauthorized requests to the vulnerable endpoint and executing actions without the admin's consent.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.