CVE-2021-32101

Source
https://cve.org/CVERecord?id=CVE-2021-32101
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32101.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-32101
Published
2021-05-07T04:15:07.387Z
Modified
2026-07-09T00:05:36.388219Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
[none]
Details

The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/machineconfig.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.

References

Affected packages

Git / github.com/openemr/openemr

Affected ranges

Type
GIT
Repo
https://github.com/openemr/openemr
Events
Database specific
Show details
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:open-emr:openemr:5.0.2.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "5.0.2.1"
        },
        {
            "last_affected": "5.0.2.1"
        }
    ]
}

Affected versions

5.*
5.0.2.1
Other
v5_0_2_1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32101.json"