CVE-2021-44160 Information
Jun 07, 2022
cve
Description
Carinal Tien Hospital Health Report System’s login page has improper authentication a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data making the service partially unavailable to the user.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Reference
https://www.twcert.org.tw/tw/cp-132-5429-4185b-1.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
7.3
Share on: