CVE-2023-0959: Imaworldhealth Bhima
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. This is possible because the application is vulnerable to CSRF.
Affected products
- Imaworldhealth Bhima: version 1.27.0 only
Published 2023-04-05. Last modified 2026-06-17.