CVE-2024-26492: ORETNOM23 Online Diagnostic Lab Management System

Medium severity, CVSS 6.3. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue in Online Diagnostic Lab Management System 1.0 allows a remote attacker to gain control of a 'Staff' user account via a crafted POST request using the id, email, password, and cpass parameters.

Affected products

  • ORETNOM23 Online Diagnostic Lab Management System: version 1.0 only

Published 2024-03-07. Last modified 2026-06-17.