Description
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12786 | In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user. |
References
History
Wed, 30 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T17:35:01.031Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25920
Updated: 2024-08-03T20:11:28.444Z
Status : Modified
Published: 2021-03-22T20:15:17.880
Modified: 2025-04-30T18:15:34.207
Link: CVE-2021-25920
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD