Hospitals Patient Records Management System v1.0 — IDOR (Account Takeover)
Introduction I reviewed HPRMS v1.0 to assess how its admin area handles identity and authorization in routine CRUD flows. Applications with profile-edit features often expose object identifiers dir...