Vulnerability Description
The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laudo?id= URI. By manipulating this id parameter, an attacker can gain access to sensitive medical information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Modernasistemas | Modernanet Hospital Management System 2024 | - |
Related Weaknesses (CWE)
References
- https://github.com/louiselalanne/CVE-2024-23747ExploitThird Party Advisory
- https://modernasistemas.com.br/sitems/Product
- https://github.com/louiselalanne/CVE-2024-23747ExploitThird Party Advisory
- https://modernasistemas.com.br/sitems/Product
FAQ
What is CVE-2024-23747?
CVE-2024-23747 is a vulnerability with a CVSS score of 7.5 (HIGH). The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user ...
How severe is CVE-2024-23747?
CVE-2024-23747 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-23747?
Check the references section above for vendor advisories and patch information. Affected products include: Modernasistemas Modernanet Hospital Management System 2024.