First published: Fri May 12 2023(Updated: )
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | <7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2674 is a vulnerability related to improper access control in the GitHub repository openemr/openemr prior to version 7.0.1.
The Open-emr Openemr software version up to and excluding 7.0.1 is affected by CVE-2023-2674.
CVE-2023-2674 has a severity rating of high with a CVSS score of 4.3.
To fix CVE-2023-2674, it is recommended to update the openemr/openemr repository to version 7.0.1 or later.
More information about CVE-2023-2674 can be found at the following references: [GitHub Commit](https://github.com/openemr/openemr/commit/bb4244c83a74628faafabc0598366f49863914a9), [Huntr Bounty](https://huntr.dev/bounties/af73e913-730c-4245-88ce-26fc908d3644).