Carinal Tien Hospital Health Report System - Authorization Bypass Through User-Controlled Key
Description
Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or modify data, making the service partially unavailable to the user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Carinal Tien Hospital Health Report System's login page allows remote attackers to bypass authentication and assume another user's privilege by modifying a cookie parameter.
Vulnerability
The Carinal Tien Hospital Health Report System (version unknown, as the vendor did not disclose the affected version [1]) contains an improper authentication vulnerability on its login page. The system does not adequately validate the user's identity; a remote attacker can modify a cookie parameter (likely a user identifier) to impersonate any other general user without needing to authenticate [1].
Exploitation
An attacker with network access to the login page can exploit this by simply changing the value of a cookie parameter (e.g., a user ID) in an HTTP request to the server [1]. No authentication or prior access is required, and no user interaction is needed. The attacker only needs to know or guess another user's identifier (possibly sequential or predictable) [1].
Impact
Successful exploitation allows the attacker to assume the privileges of the targeted user [1]. The attacker can then perform limited operations on the system or modify data, which may cause the legitimate user to become unable to use some services [1]. The impact touches confidentiality (unauthorized access to user-specific data), integrity (unauthorized data modification), and availability (partial denial of service for the affected user) [1].
## Mitigation the hospital has updated the system to fix the vulnerability [1]. No further details about the fix or affected versions have been disclosed [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Carinal Tien Hospital/Health Report Systemv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-5429-4185b-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.