CVE-2026-90858 Details
Description
A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of the argument adminmail can lead to authorization bypass. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
An authorization bypass vulnerability has been identified in the Subhajitkhan Online Clinic Management System, specifically in the 'adminappview.php' file, prior to the commit 'e9ee77a8827a1446220fa07ee693dc4d9a29a578'. The issue arises because the 'session_start' function does not properly validate the 'adminmail' argument, allowing unauthorized users to access and manipulate administrative data. This vulnerability can be exploited remotely.
Implement a session validation check for administrative actions to ensure that only authorized users can perform these tasks. Additionally, apply Cross-Site Request Forgery (CSRF) protection to requests that modify data.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/subhajitkhan/online-clinic-management-system/ | [email protected] | ProductSource CodeVendor |
| https://github.com/subhajitkhan/online-clinic-management-system/issues/4 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-90858 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/927291 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403415 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403415/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| subhajitkhan online-clinic-management-system | <e9ee77a8827a1446220fa07ee693dc4d9a29a578 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | [email protected] |
Volerion