CVE-2026-42518
Severity CVSS v4.0:
HIGH
Type:
CWE-321
Use of Hard-coded Cryptographic Key
Publication date:
29/04/2026
Last modified:
29/04/2026
Description
This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information and cryptographic keys.<br />
<br />
Successful exploitation of this vulnerability could lead to exposure of sensitive data and compromise of cryptographic protections on the targeted system.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH



