Description
This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could exploit this vulnerability by decoding and manipulating Base64-encoded parameters in the request URL to gain unauthorized access to sensitive information on the targeted system.
Problem types
CWE-639 Authorization bypass through User-Controlled key
Product status
Previous versions (custom)
Credits
This vulnerability is reported by Harsh Verma
References
www.cert-in.org.in/...eid=PUBVLNOTES01&VLCODE=CIVN-2026-0207