CVE-2022-1461
25.04.2022, 11:15
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.Enginsight
Vendor | Product | Version |
---|---|---|
open-emr | openemr | 𝑥 < 6.1.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1220 - Insufficient Granularity of Access ControlThe product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
- CWE-639 - Authorization Bypass Through User-Controlled KeyThe system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
References