Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Contact C-DAC for upgrading e-Sushrut HMIS to latest version
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Apr 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cdac-noida e-sushrut Hmis
|
|
| Vendors & Products |
Cdac-noida e-sushrut Hmis
|
Wed, 29 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API request URL to gain unauthorized access to sensitive information of patients on the targeted system. | |
| Title | Insecure Direct Object Reference (IDOR) Vulnerability in e-Sushrut HMIS | |
| First Time appeared |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:cdac-noida:e-sushrut_hospital_management_information_system_hmis_:previous_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-04-29T12:22:26.245Z
Reserved: 2026-04-28T08:14:36.620Z
Link: CVE-2026-42515
No data.
Status : Deferred
Published: 2026-04-29T09:16:24.680
Modified: 2026-04-29T21:14:23.977
Link: CVE-2026-42515
No data.
OpenCVE Enrichment
Updated: 2026-04-29T10:10:13Z