Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/addediteventuser.php, (2) portal/findapptpopupuser.php, (3) portal/getallergies.php, (4) portal/getamendments.php, (5) portal/getlabresults.php, (6) portal/getmedications.php, (7) portal/getpatientdocuments.php, (8) portal/getproblems.php, (9) portal/getprofile.php, (10) portal/portalpayment.php, (11) portal/messaging/messages.php, (12) portal/messaging/securechat.php, (13) portal/report/patledger.php, (14) portal/report/portalcustomreport.php, or (15) portal/report/portalpatientreport.php without authenticating as a patient.