Impact
A flaw exists in the adminappview.php handler of the online‑clinic‑management‑system, where the session_start function incorrectly accepts a manipulated adminmail argument, allowing attackers to bypass authorization. The remote attack can be launched by sending crafted requests to the affected endpoint, and published exploits confirm the vulnerability’s practical use.
Affected Systems
The vulnerability affects the open source online‑clinic‑management‑system released by subhajitkhan, all iterations up to commit e9ee77a8827a1446220fa07ee693dc4d9a29a578. No patched version is available, and the product’s continuous delivery pipeline does not provide separate numbered releases.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability score is less than 1% and the issue is not listed in CISA’s KEV catalog, suggesting limited current exploitation activity. However, remote attackers can exploit the flaw by manipulating the adminmail parameter, achieving unauthorized access to administrative functions. The problem falls under CWE-285 (Unauthorized Access) and CWE-639 (Authorization Bypass Through User‑Controlled Key), both of which facilitate privilege escalation if not mitigated.
OpenCVE Enrichment