Impact
The vulnerability resides in the HospitalManagement password change handler, where manipulation of the kode_user/username argument bypasses the expected authentication checks. This flaw allows an attacker to submit a crafted request to the password change endpoint and log in as another user without knowing that user's credentials, effectively achieving an unauthorized authentication bypass.
Affected Systems
The affected product is ged specific version numbers are available because the project uses a rolling release model; the vulnerability exists in all releases up to the commit c2d45543789a3887067d3915f69d44cfc2cf76a8. The issue was reported but the maintainer has not yet released a fix.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of < 1% and the entry is not listed in CISA’s KEV catalog, so no widespread exploitation has been documented. The CVE notes that the attack may be launched remotely, implying that an attacker can exercise the flaw by sending crafted HTTP requests to the password change endpoint. Without a patch or mitigation, the vulnerability remains exploitable.
OpenCVE Enrichment