CVE Details
Basic Information
| Title | CodeAstro Patient Record Management System cross-site request forgery |
|---|---|
| Type | cve |
| Published | 2025-06-25T20:31:06.261Z |
| Last Seen |
Product Information
| Vendor | CodeAstro |
|---|---|
| Product | Patient Record Management System |
| Version | 1.0 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A medium-severity cross-site request forgery (CSRF) vulnerability was discovered in CodeAstro Patient Record Management System version 1.0. This vulnerability allows remote attackers to perform unauthorized actions on behalf of authenticated users without their knowledge. CSRF attacks can lead to data modification or unauthorized access, posing a significant risk, especially in healthcare systems where patient data is sensitive. |
|---|---|
| AI Severity | Medium |
| Vendor | CodeAstro |
| Product | Patient Record Management System |
| Affected Version | 1.0 |
Affected Products
- CodeAstro Patient Record Management System 1.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-352, CWE-862 |
| Bulletin Family |
References
- https://vuldb.com/?id.313878
- https://vuldb.com/?ctiid.313878
- https://vuldb.com/?submit.602323
- https://github.com/Vanshdhawan188/CodeAstro-Online-Healthcare-Patient-Record-Management-System-CSRF/blob/main/CodeAstro-Online-Healthcare-Patient-Record-Management-System-CSRF.md
- https://github.com/Vanshdhawan188/CodeAstro-Online-Healthcare-Patient-Record-Management-System-CSRF/blob/main/CodeAstro-Online-Healthcare-Patient-Record-Management-System-CSRF.md#-steps-to-reproduce
- https://codeastro.com/
Description
A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.