Impact
The vulnerability is located in the update_subaccount function of the Account Administration controller, where manipulation of the user_id parameter removes proper authorization checks. An attacker who can reach the endpoint can override the target subaccount and perform unauthorized changes, leading to unauthorized modification of user data and potential privilege escalation. The weakness corresponds to incorrect privilege assignment and incorrect authorization controls.
Affected Systems
The flaw affects onetwothreeneth’s HospitalManagementSystem. All releases up to commit 9ef91ed6007314b6473110ed699dff76d158f61d are impacted. No specific version is reported due to the rolling‑release model, but any copy of the current code base before the fix contains the issue.
Risk and Exploitability
The CVSS base score is 6.9, indicating a moderate‑to‑high severity. EPSS data is not available, yet an exploit is published and listed in publicly available resources, meaning remote attackers can utilize this flaw. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can reach the web interface remotely to send crafted requests, exploiting the missing authorization checks. Because the attack is remote and the exploit exists, the risk is elevated beyond the CVSS rating.
OpenCVE Enrichment