Impact
The Vulnerability allows unauthenticated remote attackers to obtain confidential information that is embedded in URLs. Because the parameters are transmitted as part of the URL, they may be stored in browser history or server logging files, giving attackers a secondary avenue to access the data after initial exposure. The primary confidentiality impact is that private patient information or other protected data may be leaked to unauthorized parties. The weakness is identified as CWE‑598, which is an evidence of sensitive data exposure in user-facing channels.
Affected Systems
The affected product is the Le‑yan Medical Practice Management System. The vendor recommends upgrading to version 2.5.2.0 or later. No precise affected version list is supplied, implying that any version prior to 2.5.2.0 may be vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that the likelihood of exploitation is not currently documented as high. Attackers can exploit the flaw remotely without authentication, likely by crafting URLs containing sensitive data and directing a victim to visit them. Once the URL is accessed, the data can be retrieved from the victim’s browser history or from server logs that capture the full query string.
OpenCVE Enrichment