CVE-2024-45983

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Sep 30, 2024
CWE ID 352

Summary

CVE-2024-45983 is a Cross-Site Request Forgery (CSRF) vulnerability affecting kishan0725's Hospital Management System version 6.3.5. This issue enables attackers to create malicious HTML forms that trick authenticated admin users into visiting the malicious webpage. Once the user visits the page, the attacker can leverage their browser to make unauthorized requests to delete doctor records, effectively carrying out actions on behalf of the admin without their consent. This vulnerability poses a significant risk to the security of doctor records within the hospital management system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Hospital Management System

Affected Vendors

  • Codezips