PT-2021-24054 · Unknown · Carinal Tien Hospital Health Report System

Chen

+2

·

Published

2021-12-29

·

Updated

2022-08-09

·

CVE-2021-44160

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Carinal Tien Hospital Health Report System (affected versions not specified)
Description: The system's login page has improper authentication, allowing a remote attacker to acquire another user's privilege by modifying the cookie parameter without authentication. This enables the attacker to perform limited operations on the system, modify data, and make the service partially unavailable to the user.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44160

Affected Products

Carinal Tien Hospital Health Report System