Impact
An attacker can send a crafted request to php/sessions.php with a manipulated ID parameter, causing the application to believe the request originates from a legitimate, authenticated session. As a result, the attacker can impersonate an existing user, elevate privileges, and access protected resources such as patient records, appointments, or administrative features. The flaw allows an unauthenticated user to bypass standard authentication checks, directly impacting the confidentiality and integrity of sensitive health data.
Affected Systems
The affected application is onetwothreeneth’s HospitalManagementSystem, any release built on or before the commit 9ef91ed6007314b6473110ed699dff76d158f61d. The project uses a rolling release model, so the vulnerability may exist in newer commits until an official fix is released. No version numbers are available, but any deployment that pulls from the repository without updating past that commit is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 6.9 indicates a medium severity threat. The EPSS score is not available, but publicly disclosed exploitation code exists, and the weakness allows remote exploitation via standard HTTP requests. The vulnerability is not in CISA’s KEV catalog, yet the lack of a patch and the nature of the flaw suggest a realistic chance of abuse in environments exposed to the internet. Therefore, the risk to organizations running the unpatched system is moderate to high, especially for those handling sensitive patient information that could be read or tampered with by a malicious actor.
OpenCVE Enrichment