CVE-2022-1177

Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*

History

04 Apr 2022, 19:40

Type Values Removed Values Added
CPE cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*
CWE CWE-1220 CWE-863
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
References (CONFIRM) https://huntr.dev/bounties/0bb2979b-9643-4cdf-ab58-4354976b481b - (CONFIRM) https://huntr.dev/bounties/0bb2979b-9643-4cdf-ab58-4354976b481b - Exploit, Patch, Third Party Advisory
References (MISC) https://github.com/openemr/openemr/commit/a2e918abcf15f9fc1f7cb4a1f2b09ff019021175 - (MISC) https://github.com/openemr/openemr/commit/a2e918abcf15f9fc1f7cb4a1f2b09ff019021175 - Patch, Third Party Advisory

30 Mar 2022, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-30 11:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-1177

Mitre link : CVE-2022-1177

CVE.ORG link : CVE-2022-1177


JSON object : View

Products Affected

open-emr

  • openemr
CWE
CWE-863

Incorrect Authorization

CWE-1220

Insufficient Granularity of Access Control