Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability
# CVE-2024-23747
The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability.
## PoC
This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laudo?id= URL. Bymanipulating this id parameter, an attacker can gain access to sensitive medical information.
http://IP/Modernanet/LAUDO/LAU0000100/Laudo?id=NUMBER

You don't need to be logged in to see the results.
## Bonus
It was possible to access this hospital's user account because of weak credentials that can be obtained through this IDOR.

## Reference
https://modernasistemas.com.br/sitems/
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view