What the vulnerability does
01Description
Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
Explanation of Vulnerability in Simple Terms
KiviCare versions up to 4.5.1 contain an authentication bypass vulnerability that allows attackers to access the system without valid credentials. The flaw exists in an alternate authentication path or channel, enabling unauthorized access to sensitive data. No user interaction or special privileges are required to exploit this issue.
What an attacker can do
Access the system and read sensitive data without providing valid login credentials.
Potential impact on your site
Unauthorized users can view confidential patient or business data stored in KiviCare without logging in.
Conditions required to exploit
Network access to the KiviCare installation; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities