An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.
Link | Tags |
---|---|
https://github.com/A3h1nt/CVEs/tree/main/OpenEMR | third party advisory exploit |
https://github.com/openemr/openemr/pull/7435#event-12872646667 | patch vendor advisory |