
All Details about CVE-2022-22296
Software: Hospital's Patient Records Management System 1.0
Software Link: https://www.sourcecodester.com/php/15116/hospitals-patient-records-management-system-php-free-source-code.html
Vulnerability Type: Insecure Permissions - IDOR
Affected Component: id parameter in Change User Function
Impact Escalation of Privileges: true
Attack Type: Remote
Vendor of Product: Sourcecodester
Impact: This vulnerability allows an attacker to edit information that do not belong to him and remove them from the users account.