Описание
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.
Ссылки
- ProductThird Party Advisory
- Not Applicable
- Vendor Advisory
- ProductThird Party Advisory
- Not Applicable
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:open-emr:openemr:6.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01304
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-639
Связанные уязвимости
CVSS3: 8.1
github
почти 4 года назад
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.
EPSS
Процентиль: 79%
0.01304
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-639