HIGH SeverityCVSS 4.08.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CVE-2026-42513
Last updated Apr 29, 2026 · Published Apr 29, 2026
Description
This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vulnerability by intercepting and modifying the server response. Successful exploitation of this vulnerability could allow the attacker to bypass authentication and gain unauthorized access to user accounts on the targeted system.
Affected products
2 listed- CDAC-Noida:e-Sushrut
- Hospital Management Information System (HMIS)
Mappings
CWE
None listed.
CAPEC
CAPEC-115
Related
Guides
CVE® content © MITRE Corporation. Licensed under the CVE Terms of Use. Terms
