CVE-2024-45983
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Summary
CVE-2024-45983 is a Cross-Site Request Forgery (CSRF) vulnerability affecting kishan0725's Hospital Management System version 6.3.5. This issue enables attackers to create malicious HTML forms that trick authenticated admin users into visiting the malicious webpage. Once the user visits the page, the attacker can leverage their browser to make unauthorized requests to delete doctor records, effectively carrying out actions on behalf of the admin without their consent. This vulnerability poses a significant risk to the security of doctor records within the hospital management system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Hospital Management System
Affected Vendors
- Codezips