PT-2026-49167 · Medkey · Medkey

Onyxglitch

·

Published

2026-06-15

·

Updated

2026-06-15

·

CVE-2026-12207

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions medkey-org medkey versions up to fc09b7ba9441ff590b72d428d5380834216b09ed
Description An issue in the HTTP REST API component allows remote attackers to manipulate the ID argument within the actionGetPatientById() function of the appmodulesmedicalportrestcontrollersPatientController.php file. This leads to improper control of resource identifiers, also known as resource injection, where an application does not sufficiently validate the identifiers used to access resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12207

Affected Products

Medkey