8.8
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Description
This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vulnerability by intercepting and modifying the server response.
Successful exploitation of this vulnerability could allow the attacker to bypass authentication and gain unauthorized access to user accounts on the targeted system.
Successful exploitation of this vulnerability could allow the attacker to bypass authentication and gain unauthorized access to user accounts on the targeted system.
AI Analysis
Authentication bypass vulnerability due to improper authentication logic
Basic Information
ID
CVE-2026-42513
Source
CERT-In
Published
Apr 29, 2026 at 08:13
Affected Product
Vendor
CDAC-Noida
Product
e-Sushrut, Hospital Management Information System (HMIS)
Version
Previous versions
Affected Versions
CDAC-Noida e-Sushrut, Hospital Management Information System (HMIS) Previous versions
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
CDAC-Noida
Product
e-Sushrut HMIS
Version
Previous versions