445
VMScore

CVE-2022-22296

Published: 24/01/2022 Updated: 28/01/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. Simply change the value and data of other users can be displayed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hospital's patient records management system project hospital's patient records management system 1.0

Github Repositories

All Details about CVE-2022-22296

CVE-2022-22296 All Details about CVE-2022-22296 Software: Hospital's Patient Records Management System 10 Software Link: wwwsourcecodestercom/php/15116/hospitals-patient-records-management-system-php-free-source-codehtml Vulnerability Type: Insecure Permissions - IDOR Affected Component: id parameter in Change User Function Impact Escalation of Privileges: true