<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:26:58 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-42515 — Insecure Direct Object Reference (IDOR) Vulnerability in e-Sushrut HMIS</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-42515</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CDAC-Noida e-Sushrut, Hospital Management Information System (HMIS)&lt;/p&gt;
&lt;p&gt;This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API request URL to gain unauthorized access to sensitive information of patients on the targeted system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CDAC-Noida e-Sushrut, Hospital Management Information System (HMIS)&lt;/p&gt;
&lt;p&gt;This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API request URL to gain unauthorized access to sensitive information of patients on the targeted system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-42515</guid>
    </item>
  </channel>
</rss>
