CVE-2021-32101
To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- open-emr/openemr
- Source
- cve@mitre.org
References
- https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerabilityThird Party Advisory
- https://community.open-emr.org/t/openemr-5-0-2-patch-5-has-been-released/15431Vendor Advisory
- https://community.sonarsource.com/t/openemr-5-0-2-1-command-injection-vulnerability-puts-health-records-at-risk/33592Third Party Advisory
- https://portswigger.net/daily-swig/healthcare-security-openemr-fixes-serious-flaws-that-lead-to-command-execution-in-patient-portalThird Party Advisory
- https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerabilityThird Party Advisory
- https://community.open-emr.org/t/openemr-5-0-2-patch-5-has-been-released/15431Vendor Advisory
- https://community.sonarsource.com/t/openemr-5-0-2-1-command-injection-vulnerability-puts-health-records-at-risk/33592Third Party Advisory
- https://portswigger.net/daily-swig/healthcare-security-openemr-fixes-serious-flaws-that-lead-to-command-execution-in-patient-portalThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.