Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-5429-4185b-1.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2021-12-29T07:15:15.313516Z
Updated: 2024-09-16T23:15:39.424Z
Reserved: 2021-11-23T00:00:00
Link: CVE-2021-44160
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-12-29T08:15:06.703
Modified: 2024-11-21T06:30:28.230
Link: CVE-2021-44160
Redhat
No data.