Description
A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of the argument adminmail can lead to authorization bypass. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass
Action: Apply Workaround
AI Analysis

Impact

A flaw exists in the adminappview.php handler of the online‑clinic‑management‑system, where the session_start function incorrectly accepts a manipulated adminmail argument, allowing attackers to bypass authorization. The remote attack can be launched by sending crafted requests to the affected endpoint, and published exploits confirm the vulnerability’s practical use.

Affected Systems

The vulnerability affects the open source online‑clinic‑management‑system released by subhajitkhan, all iterations up to commit e9ee77a8827a1446220fa07ee693dc4d9a29a578. No patched version is available, and the product’s continuous delivery pipeline does not provide separate numbered releases.

Risk and Exploitability

With a CVSS score of 6.9 the vulnerability score is less than 1% and the issue is not listed in CISA’s KEV catalog, suggesting limited current exploitation activity. However, remote attackers can exploit the flaw by manipulating the adminmail parameter, achieving unauthorized access to administrative functions. The problem falls under CWE-285 (Unauthorized Access) and CWE-639 (Authorization Bypass Through User‑Controlled Key), both of which facilitate privilege escalation if not mitigated.

Generated by OpenCVE AI on September 17, 2026 at 18:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Manually modify adminappview.php to validate the adminmail parameter against a whitelist of legitimate administrator email addresses, rejecting any unexpected values.
  • Replace the default session_start usage with secure session handling: regenerate session IDs on login, set session cookies to HttpOnly, Secure, and SameSite=Strict, and enforce TLS‑only cookies to limit session fixation.
  • Implement server‑side logging and alerting to capture any attempts to manipulate the adminmail parameter, and block such requests to reduce the risk of successful bypass.

Generated by OpenCVE AI on September 17, 2026 at 18:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of the argument adminmail can lead to authorization bypass. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Title subhajitkhan online-clinic-management-system adminappview.php session_start authorization
First Time appeared Subhajitkhan
Subhajitkhan online-clinic-management-system
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:subhajitkhan:online-clinic-management-system:*:*:*:*:*:*:*:*
Vendors & Products Subhajitkhan
Subhajitkhan online-clinic-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Subhajitkhan Online-clinic-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:55:16.834Z

Reserved: 2026-09-14T05:52:31.266Z

Link: CVE-2026-90858

cve-icon Vulnrichment

Updated: 2026-09-15T17:55:12.807Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T04:18:20.010

Modified: 2026-09-15T18:19:38.383

Link: CVE-2026-90858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key