The Moderna Sistemas ModernaNet Hospital Management...
High severity
Unreviewed
Published
Jan 29, 2024
to the GitHub Advisory Database
•
Updated Feb 10, 2024
Description
Published by the National Vulnerability Database
Jan 29, 2024
Published to the GitHub Advisory Database
Jan 29, 2024
Last updated
Feb 10, 2024
The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laudo?id= URI. By manipulating this id parameter, an attacker can gain access to sensitive medical information.
References