CVE-2022-1177
30.03.2022, 11:15
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.Enginsight
Vendor | Product | Version |
---|---|---|
open-emr | openemr | 𝑥 < 6.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1220 - Insufficient Granularity of Access ControlThe product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References