Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/kabirkhyrul/HMS | product third party advisory |
https://github.com/kabirkhyrul/HMS/discussions/12 | third party advisory issue tracking exploit |