Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/addediteventuser.php, (2) portal/findapptpopupuser.php, (3) portal/getallergies.php, (4) portal/getamendments.php, (5) portal/getlabresults.php, (6) portal/getmedications.php, (7) portal/getpatientdocuments.php, (8) portal/getproblems.php, (9) portal/getprofile.php, (10) portal/portalpayment.php, (11) portal/messaging/messages.php, (12) portal/messaging/securechat.php, (13) portal/report/patledger.php, (14) portal/report/portalcustomreport.php, or (15) portal/report/portalpatientreport.php without authenticating as a patient.
{
"cpe": "cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "5.0.1.4"
}
],
"source": "CPE_RANGE"
}