CVE-2026-42518

This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information and cryptographic keys. Successful exploitation of this vulnerability could lead to exposure of sensitive data and compromise of cryptographic protections on the targeted system.
CVSS

No CVSS.

Configurations

No configuration.

History

29 Apr 2026, 21:14

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-29 09:16

Updated : 2026-04-29 21:14


NVD link : CVE-2026-42518

Mitre link : CVE-2026-42518

CVE.ORG link : CVE-2026-42518


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key