First published: Mon Apr 30 2018(Updated: )
interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the newtemplatename and form_body parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10572 is rated as a high severity vulnerability due to its potential for unauthorized access.
To address CVE-2018-10572, upgrade OpenEMR to version 5.0.1 or later, which contains the necessary security patches.
CVE-2018-10572 affects OpenEMR versions prior to 5.0.1, specifically allowing remote authenticated users to exploit access restrictions.
The vulnerability in CVE-2018-10572 is found in the interface/patient_file/letter.php component of OpenEMR.
No, CVE-2018-10572 requires authenticated users to exploit the vulnerability and bypass access restrictions.