JustAppSec
HIGH SeverityCVSS 4.07.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-42517

Last updated Apr 29, 2026 · Published Apr 29, 2026

← Back to list

Description

This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could exploit this vulnerability by decoding and manipulating Base64-encoded parameters in the request URL to gain unauthorized access to sensitive information on the targeted system.

Affected products

2 listed
  • CDAC-Noida:e-Sushrut
  • Hospital Management Information System (HMIS)

Mappings

CWE

CWE-639

CAPEC

CAPEC-566

Related


CVE® content © MITRE Corporation. Licensed under the CVE Terms of Use. Terms

Need help?Get in touch.