CVE-2022-1459
25.04.2022, 10:15
Non-Privilege User Can View Patients Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.Enginsight
Vendor | Product | Version |
---|---|---|
open-emr | openemr | 𝑥 < 6.1.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1118 - Insufficient Documentation of Error Handling TechniquesThe documentation does not sufficiently describe the techniques that are used for error handling, exception processing, or similar mechanisms.
- CWE-639 - Authorization Bypass Through User-Controlled KeyThe system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
References