Junglewise Threat Intelligence

CVE-2026-82181: Le-yan Medical Practice Management System sensitive data in URL

CVE-2026-82181 · Severity: medium · CVSS 5.5 · Published 2026-08-28

Executive brief

Le-yan's Medical Practice Management System is used to manage patient records and medical practice operations. The system leaks sensitive information through URLs, allowing attackers to recover this data from browser history or server logs. An unauthenticated attacker can exploit this to access confidential medical information without proper authorization.

Technical details

This vulnerability is a Sensitive Data in URL issue affecting Le-yan Medical Practice Management System versions 2.4.2.8 through 2.5.1.9. The vulnerability allows unauthenticated remote attackers to obtain sensitive information by accessing browser history or log files that contain URLs with embedded sensitive data. The attack requires no authentication and no special privileges, and the vulnerable parameter is accessible via local access (local attack vector). An attacker can recover confidential patient information and medical data exposed in URL parameters. The vendor has released patches in version 2.5.2.0 and later.

Affected products

  • Le-yan Medical Practice Management System 2.4.2.8 to 2.5.1.9

Timeline

  • 2026-08-25: disclosed
  • 2026-08-28: advisory

References

Related threats