JustAppSec
HIGH SeverityCVSS 4.08.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

CVE-2026-42513

Last updated Apr 29, 2026 · Published Apr 29, 2026

← Back to list

Description

This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vulnerability by intercepting and modifying the server response. Successful exploitation of this vulnerability could allow the attacker to bypass authentication and gain unauthorized access to user accounts on the targeted system.

Affected products

2 listed
  • CDAC-Noida:e-Sushrut
  • Hospital Management Information System (HMIS)

Mappings

CWE

None listed.

CAPEC

CAPEC-115

Related


CVE® content © MITRE Corporation. Licensed under the CVE Terms of Use. Terms

Need help?Get in touch.