CVE-2023-54347

Source
https://cve.org/CVERecord?id=CVE-2023-54347
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54347.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-54347
Published
2026-05-05T11:24:50Z
Modified
2026-08-12T03:51:20Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenEMR 7.0.1 Authentication Brute Force Mitigation Bypass
Details

OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated login attempts to the main login endpoint. Attackers can submit POST requests with authUser and clearPass parameters to systematically test username and password combinations without account lockout restrictions.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-307"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54347.json"
}
References

Affected packages

Git / github.com/openemr/openemr

Affected ranges

Type
GIT
Repo
https://github.com/openemr/openemr
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:open-emr:openemr:7.0.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "7.0.1"
        },
        {
            "last_affected": "7.0.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

7.*
7.0.1
Other
v7_0_1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54347.json"