Data Exposure in e-Sushrut by Protecting Sensitive Information Ineffectively
CVE-2026-42517
7.1HIGH
What is CVE-2026-42517?
The vulnerability in e-Sushrut arises from the use of reversible Base64 encoding to protect sensitive data. This flawed approach enables authenticated attackers to decode and manipulate Base64-encoded parameters found in request URLs, potentially granting unauthorized access to sensitive information stored in the system. It highlights the importance of implementing stronger data protection mechanisms to mitigate such vulnerabilities effectively.
Affected Version(s)
e-Sushrut, Hospital Management Information System (HMIS) Previous versions
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability is reported by Harsh Verma
