Sensitive Data Exposure in Medical Practice Management System by Le-yan
CVE-2026-82181

6.8MEDIUM

Key Information:

Vendor

Le-yan

Vendor
CVE Published:
28 August 2026

What is CVE-2026-82181?

The Medical Practice Management System developed by Le-yan has a vulnerability that allows unauthenticated remote attackers to access sensitive information. This vulnerability occurs when sensitive data is exposed in URLs, which can then be harvested through victims' browser histories or log files. This poses a risk of unauthorized information disclosure, affecting user privacy and system integrity.

Affected Version(s)

Medical Practice Management System 2.4.2.8 <= 2.5.1.9

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.