CVE-2023-0959: Imaworldhealth Bhima

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. This is possible because the application is vulnerable to CSRF.

Affected products

Published 2023-04-05. Last modified 2026-06-17.