CVE-2021-40352

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/09/2021
Last modified:
03/05/2022

Description

OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:open-emr:openemr:6.0.0:*:*:*:*:*:*:*