C-DAC e-Sushrut Improper Authorization Vulnerability Allowing Unauthorized Access to Patient Accounts

Vulnerability

A vulnerability in the C-DAC e-Sushrut Hospital Management Information System (HMIS) has been identified, stemming from inadequate authorization checks during resource access. This flaw enables authenticated attackers to manipulate encoded parameters in the request URL, potentially gaining unauthorized access to patient accounts within the system.

Impact

Exploitation of this vulnerability could lead to unauthorized access to patient accounts, allowing attackers to view or manipulate sensitive medical information.

Remediation

Users are advised to contact C-DAC for instructions on upgrading to the latest version of the e-Sushrut HMIS.

Added: Apr 29, 2026, 9:20 AM
Updated: Apr 29, 2026, 9:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
7.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.