First published: Mon Mar 22 2021(Updated: )
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | >=2.7.2<=6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25920 is classified as a high severity vulnerability due to improper access control in OpenEMR.
To fix CVE-2021-25920, update your OpenEMR installation to version 6.0.0 or later.
CVE-2021-25920 affects OpenEMR versions from 2.7.2-rc1 to 6.0.0.
CVE-2021-25920 allows an attacker to read and send sensitive messages on behalf of the victim user.
Yes, CVE-2021-25920 indicates that user authentication and access control mechanisms are improperly configured.