Description
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.
Published: 2026-08-28
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Vulnerability allows unauthenticated remote attackers to obtain confidential information that is embedded in URLs. Because the parameters are transmitted as part of the URL, they may be stored in browser history or server logging files, giving attackers a secondary avenue to access the data after initial exposure. The primary confidentiality impact is that private patient information or other protected data may be leaked to unauthorized parties. The weakness is identified as CWE‑598, which is an evidence of sensitive data exposure in user-facing channels.

Affected Systems

The affected product is the Le‑yan Medical Practice Management System. The vendor recommends upgrading to version 2.5.2.0 or later. No precise affected version list is supplied, implying that any version prior to 2.5.2.0 may be vulnerable.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that the likelihood of exploitation is not currently documented as high. Attackers can exploit the flaw remotely without authentication, likely by crafting URLs containing sensitive data and directing a victim to visit them. Once the URL is accessed, the data can be retrieved from the victim’s browser history or from server logs that capture the full query string.

Generated by OpenCVE AI on August 28, 2026 at 16:50 UTC.

Remediation

Vendor Solution

Update to version 2.5.2.0 or later


OpenCVE Recommended Actions

  • Apply the vendor patch to version 2.5.2.0 or later
  • Configure the application to avoid including sensitive information in URL parameters and instead use POST requests or encrypted payloads
  • Ensure that server and application logs are configured to exclude query strings containing confidential data

Generated by OpenCVE AI on August 28, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Le-yan
Le-yan medical Practice Management System
Vendors & Products Le-yan
Le-yan medical Practice Management System

Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.
Title Le-yan|Medical Practice Management System - Sensitive Data in URL
Weaknesses CWE-598
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Le-yan Medical Practice Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-08-28T18:27:53.436Z

Reserved: 2026-08-28T07:22:58.938Z

Link: CVE-2026-82181

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-28T16:18:31.793

Modified: 2026-08-28T20:20:15.180

Link: CVE-2026-82181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:31:58Z

Weaknesses
  • CWE-598

    Use of HTTP Request With Sensitive Query String