9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserData, modify drug inventory, and access private medical prescription data via /api/doctorOder.
AI Analysis
Unauthenticated API endpoint vulnerability in LalanaChami Pharmacy Management System allowing remote attackers to access sensitive data and modify inventory.
Basic Information
ID
CVE-2026-31071
Source
mitre
Published
May 19, 2026 at 00:00
Modified
May 20, 2026 at 13:59
Affected Product
Vendor
LalanaChami
Product
LalanaChami Pharmacy Management System
Version
5c3d028
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
LalanaChami
Product
LalanaChami Pharmacy Management System
Version
5c3d028