CVE-2026-42518
Received Received - Intake
Information Disclosure via Hardcoded AES Keys in e-Sushrut Client-Side JavaScript

Publication date: 2026-04-29

Last updated on: 2026-04-29

Assigner: Indian Computer Emergency Response Team (CERT-In)

Description
This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information and cryptographic keys. Successful exploitation of this vulnerability could lead to exposure of sensitive data and compromise of cryptographic protections on the targeted system.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-29
Last Modified
2026-04-29
Generated
2026-05-07
AI Q&A
2026-04-29
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in e-Sushrut due to the disclosure of sensitive information and hardcoded AES encryption keys within client-side JavaScript code.

An unauthenticated remote attacker can exploit this by accessing the client-side code to extract sensitive information and cryptographic keys.


How can this vulnerability impact me? :

Successful exploitation of this vulnerability could lead to exposure of sensitive data.

It could also compromise the cryptographic protections on the targeted system, potentially allowing attackers to bypass security measures.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

This vulnerability involves disclosure of sensitive information and hardcoded AES encryption keys, which could lead to exposure of sensitive data and compromise of cryptographic protections.

Such exposure and compromise of sensitive data protections can negatively impact compliance with common standards and regulations like GDPR and HIPAA, which require safeguarding personal and sensitive information.


Can you explain this vulnerability to me?

This vulnerability exists in e-Sushrut due to the disclosure of sensitive information and hardcoded AES encryption keys within client-side JavaScript code.

An unauthenticated remote attacker can exploit this by accessing the client-side code to extract sensitive information and cryptographic keys.


How can this vulnerability impact me? :

Successful exploitation of this vulnerability could lead to exposure of sensitive data.

It could also compromise the cryptographic protections on the targeted system, potentially allowing attackers to bypass security measures.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart