CVE-2022-1459
8.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Exploitability: 2.8 / Impact: 5.5
Source: NVD
Description
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
Affected (1)
Related CWEs
CWE-1118
Insufficient Documentation of Error Handling Techniques
The documentation does not sufficiently describe the techniques
that are used for error handling, exception processing, or similar
mechanisms.
CWE-639
Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
References (4)
Source: security@huntr.dev
PatchThird Party Advisory
Source: security@huntr.dev
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Timeline
No history available yet.