Impact
OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, any authenticated user could invoke the startHl7ArchiveMigration method, which should be restricted to administrator accounts. This access control flaw allows a non‑admin authenticated user to trigger administrative DWR services. The vulnerability is rooted in improper privilege management (CWE‑285).
Affected Systems
The vulnerability affects the OpenMRS legacyui-api module in releases prior to version 1.23.0 in the 1.x line and prior to version 2.10.0 in the 2.x line. Subsequent releases, 1.23.0 and 2.10.0, contain the patch that removes the flaw.
Risk and Exploitability
The CVSS base score of 8.7 indicates high severity. An EPSS score of < 1% and the absence of a CISA KEV listing suggest a low probability of exploitation in the wild. Because the method requires authentication, the attacker must already be authenticated to OpenMRS; the likely attack vector is authenticated application‑level access. This access control weakness permits any authenticated user to invoke the startHl7ArchiveMigration method, which should be reserved for administrators. Based on the description, it is inferred that the method may alter HL7 configuration, and this inferred Applying the vendor‑supplied fix mitigates the risk.
OpenCVE Enrichment