CVE-2024-26492: ORETNOM23 Online Diagnostic Lab Management System
Medium severity, CVSS 6.3. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue in Online Diagnostic Lab Management System 1.0 allows a remote attacker to gain control of a 'Staff' user account via a crafted POST request using the id, email, password, and cpass parameters.
Affected products
- ORETNOM23 Online Diagnostic Lab Management System: version 1.0 only
Published 2024-03-07. Last modified 2026-06-17.