Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-2316— Bdtask Hospital AutoManager Update Bill Page cross-site request forgery

CVSS 4.3 · Medium EPSS 0.14% · P33
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-2316

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bdtask Hospital AutoManager Update Bill Page cross-site request forgery
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability has been found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This vulnerability affects unknown code of the file /billing/bill/edit/ of the component Update Bill Page. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-256270 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
跨站请求伪造(CSRF)
Source: NVD (National Vulnerability Database)
Vulnerability Title
BDTASK Hospital AutoManager 跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
BDTASK Hospital AutoManager是孟加拉国BDTASK公司的一款强大的医院管理软件。 BDTASK Hospital AutoManager 20240227及之前版本存在跨站请求伪造漏洞,该漏洞源于文件/billing/bill/edit/会导致跨站请求伪造。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
BdtaskHospital AutoManager 20240227 -

II. Public POCs for CVE-2024-2316

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-2316

登录查看更多情报信息。

Same Patch Batch · Bdtask · 2024-03-08 · 6 CVEs total

CVE-2024-22774.3 MEDIUMBdtask G-Prescription Gynaecology & OBS Consultation Software Password Reset change_passwo
CVE-2024-23173.8 LOWBdtask Hospital AutoManager Prescription Page improper authorization
CVE-2024-22742.4 LOWBdtask G-Prescription Gynaecology & OBS Consultation Software Prescription Dashboard Index
CVE-2024-22752.4 LOWBdtask G-Prescription Gynaecology & OBS Consultation Software OBS Patient/Gynee Prescripti
CVE-2024-22762.4 LOWBdtask G-Prescription Gynaecology & OBS Consultation Software Edit Venue Page cross site s

IV. Related Vulnerabilities

V. Comments for CVE-2024-2316

No comments yet


Leave a comment