A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic key . The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been published and may be used.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Hospital_management_system | Fabian | 1.0 (including) | 1.0 (including) |