First published: Wed Feb 10 2021(Updated: )
An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can redirect users to an arbitrary URL. An attacker can provide a crafted URL to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | =5.0.2 | |
Phpgacl Project Phpgacl | =3.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13565 is an open redirect vulnerability that exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2, and OpenEMR development version 6.0.0.
CVE-2020-13565 affects OpenEMR version 5.0.2 and phpGACL version 3.3.7.
The severity of CVE-2020-13565 is medium, with a CVSS base score of 6.1.
A specially crafted HTTP request can redirect users to an arbitrary URL.
Currently, there is no available fix for CVE-2020-13565. It is recommended to follow the vendor's advisory for any updates or patches.