This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could exploit this vulnerability by decoding and manipulating Base64-encoded parameters in the request URL to gain unauthorized access to sensitive information on the targeted system.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
Contact C-DAC for upgrading e-Sushrut HMIS to latest version
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Apr 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could exploit this vulnerability by decoding and manipulating Base64-encoded parameters in the request URL to gain unauthorized access to sensitive information on the targeted system. | |
| Title | Cryptographic Failure Vulnerability in e-Sushrut HMIS | |
| First Time appeared |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:cdac-noida:e-sushrut_hospital_management_information_system_hmis_:previous_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Cdac-noida
Cdac-noida e-sushrut Hospital Management Information System Hmis |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-04-29T08:30:09.583Z
Reserved: 2026-04-28T08:14:36.620Z
Link: CVE-2026-42517
No data.
Status : Received
Published: 2026-04-29T09:16:24.923
Modified: 2026-04-29T09:16:24.923
Link: CVE-2026-42517
No data.
OpenCVE Enrichment
Updated: 2026-04-29T10:00:09Z
Weaknesses