CVE-2025-50594

9.8

Danphe Health · Hospital Management System EMR

A critical vulnerability in Danphe Health Hospital Management System EMR 3.2 allows unauthenticated attackers to reset arbitrary user account passwords via the SecuritySettingsController.

Executive summary

A critical account takeover vulnerability in Danphe Health Hospital Management System EMR 3.2 allows unauthenticated attackers to reset any user password.

Vulnerability

The flaw resides in SecuritySettingsController.cs, which fails to properly validate authorization during the password reset process. This allows an unauthenticated attacker to trigger password changes for any user in the system.

Business impact

This vulnerability carries a CVSS score of 9.8, reflecting its potential for total system compromise. Unauthorized access to an EMR system can lead to the theft of sensitive Protected Health Information (PHI), violation of regulatory compliance standards (e.g., HIPAA), and severe reputational damage to the healthcare provider.

Remediation

Immediate Action: Contact the vendor immediately to obtain the necessary security patch or hotfix for version 3.2.

Proactive Monitoring: Audit user account management logs for suspicious password reset activity or unauthorized administrative actions.

Compensating Controls: Restrict access to the EMR web interface to internal, trusted networks using VPNs or strict IP whitelisting to prevent external exploitation.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability is of the highest urgency given the sensitivity of the data handled by EMR systems. Administrators must assume the system is at risk and implement strict access controls while working with the vendor to apply the corrective update.