Home
HIGH: 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N < 8.0.0
affected
Description
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not properly validate user permission. Unauthorized users can view the information of authorized users. Version 8.0.0 fixes the issue.
Problem types
CWE-863: Incorrect Authorization
Product status
References
github.com/...penemr/security/advisories/GHSA-69cv-rv28-4g85
github.com/...ommit/ad902d6892482fff2e3c56bfb15597df8b6c3beb