CVE-2026-31071

API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt password hashes) via /api/user/getUserData, modify drug inventory, and access private medical prescription data via /api/doctorOder.
Configurations

No configuration.

History

24 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Los puntos finales de la API en el Sistema de Gestión de Farmacias LalanaChami (commit 5c3d028) carecen de middleware de autenticación. Atacantes remotos no autenticados pueden explotar esto para volcar todos los registros de usuario (incluyendo hashes de contraseña bcrypt) a través de /api/user/getUserData, modificar el inventario de medicamentos y acceder a datos privados de prescripciones médicas a través de /api/doctorOder.

20 May 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
References () https://gist.github.com/nedlir/bc8ad4693c53256819280e8f5de49286 - () https://gist.github.com/nedlir/bc8ad4693c53256819280e8f5de49286 -
CWE CWE-306

19 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 16:16

Updated : 2026-07-24 12:10


NVD link : CVE-2026-31071

Mitre link : CVE-2026-31071

CVE.ORG link : CVE-2026-31071


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function