HIGH
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php
Published May 7, 2021
8.2
HIGHCVSS 3.1
EPSS 1.18%
Description
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerability x_refsource_MISCThird Party Advisory
- https://community.open-emr.org/t/openemr-5-0-2-patch-5-has-been-released/15431 x_refsource_MISCVendor Advisory
- https://community.sonarsource.com/t/openemr-5-0-2-1-command-injection-vulnerability-puts-health-records-at-risk/33592 x_refsource_MISCThird Party Advisory
- https://portswigger.net/daily-swig/healthcare-security-openemr-fixes-serious-flaws-that-lead-to-command-execution-in-patient-portal x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerability | x_refsource_MISCThird Party Advisory | |
| https://community.open-emr.org/t/openemr-5-0-2-patch-5-has-been-released/15431 | x_refsource_MISCVendor Advisory | |
| https://community.sonarsource.com/t/openemr-5-0-2-1-command-injection-vulnerability-puts-health-records-at-risk/33592 | x_refsource_MISCThird Party Advisory | |
| https://portswigger.net/daily-swig/healthcare-security-openemr-fixes-serious-flaws-that-lead-to-command-execution-in-patient-portal | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 7, 2021
Updated Aug 3, 2024
Reserved May 7, 2021
Link CVE-2021-32101
CISA Vulnrichment
Updated n/a