PicoTronica e-Clinic Healthcare System Missing Authentication Vulnerability in Patient Records API Endpoint
Vulnerability
A vulnerability in PicoTronica e-Clinic Healthcare System version 5.7 has been identified. The issue resides in an unknown function within the file '/cdemos/echs/api/v2/patient-records' of the API Endpoint component. This vulnerability allows for missing authentication, enabling remote exploitation that could lead to unauthorized access to patient records. The exploit is public and has been actively disseminated.
Impact
Exploitation of this vulnerability allows for unauthorized access to patient personally identifiable information (PII) through the patient-records API, which could lead to privacy violations and misuse of sensitive health information.
Remediation
Users are advised to upgrade to version 5.7.1 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
