VYPR
Vendor

e-Sushrut

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2026-42518HigApr 29, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information…

  • CVE-2026-42514HigApr 29, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker could exploit this vulnerability by intercepting API responses containing valid OTPs. Successful exploitation of this vulnerability could allow an attacker to…

  • CVE-2026-42513HigApr 29, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response parameters to determine authentication status. A remote attacker could exploit this vulnerability by intercepting and modifying the server response. Successful…

  • CVE-2026-42517HigApr 29, 2026
    risk 0.46cvss —epss 0.00

    This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An authenticated attacker could exploit this vulnerability by decoding and manipulating Base64-encoded parameters in the request URL to gain unauthorized access to…

  • CVE-2026-42516HigApr 29, 2026
    risk 0.46cvss —epss 0.00

    This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated attacker could exploit this vulnerability by manipulating encoded parameters in the request URL to gain unauthorized access to patient accounts on the targeted…

  • CVE-2026-42515HigApr 29, 2026
    risk 0.46cvss —epss 0.00

    This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated attacker could exploit this vulnerability by manipulating parameter in the API request URL to gain unauthorized access to sensitive information of patients on…