PT-2024-31869 · Unknown · Hospital Management System
Sourajeet Majumder
·
Published
2024-09-26
·
Updated
2024-09-30
·
CVE-2024-45983
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
kishan0725's Hospital Management System version 6.3.5
Description
A Cross-Site Request Forgery (CSRF) issue exists, allowing an attacker to craft a malicious HTML form that submits a request to delete a doctor record. By enticing an authenticated admin user to visit the specially crafted web page, the attacker can leverage the victim's browser to make unauthorized requests to the vulnerable endpoint, effectively allowing the attacker to perform actions on behalf of the admin without their consent.
Recommendations
For version 6.3.5, consider implementing proper CSRF protection mechanisms, such as token-based validation, to prevent unauthorized requests. As a temporary workaround, restrict access to the doctor record deletion functionality to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hospital Management System