CVE-2021-32101

Source
https://cve.org/CVERecord?id=CVE-2021-32101
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32101.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-32101
Published
2021-05-07T04:15:07.387Z
Modified
2026-03-15T22:37:26.590463Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
[none]
Details

The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/machineconfig.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.

References

Affected packages

Git / github.com/openemr/openemr

Affected ranges

Type
GIT
Repo
https://github.com/openemr/openemr
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "5.0.2.1"
        }
    ]
}

Affected versions

Other
v2_7_2
v2_7_2-rc1
v2_7_2-rc2
v2_7_3-rc1
v2_8_0
v2_8_1
v2_8_2
v2_8_3
v2_9_0
v3_0_0
v3_0_1
v5_0_2
v5_0_2_1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32101.json"