OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://www.open-emr.org/ | product vendor advisory |
https://github.com/openemr | product |
https://securityforeveryone.com/blog/openemr-0-day-incorrect-access-control-vulnerability-cve-2022-25041 | third party advisory |