PT-2021-24054 · Unknown · Carinal Tien Hospital Health Report System
Chen
+2
·
Published
2021-12-29
·
Updated
2022-08-09
·
CVE-2021-44160
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Carinal Tien Hospital Health Report System (affected versions not specified)
Description:
The system's login page has improper authentication, allowing a remote attacker to acquire another user's privilege by modifying the
cookie parameter without authentication. This enables the attacker to perform limited operations on the system, modify data, and make the service partially unavailable to the user.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Carinal Tien Hospital Health Report System