CVE-2024-23747: Modernasistemas Modernanet Hospital Management System 2024
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laudo?id= URI. By manipulating this id parameter, an attacker can gain access to sensitive medical information.
Affected products
- Modernasistemas Modernanet Hospital Management System 2024: affected versions not specified
Published 2024-01-29. Last modified 2026-06-17.