PT-2026-28158 · Openemr · Openemr
CVE-2026-34056
·
Publicado
2026-03-25
·
Atualizado
2026-03-26
CVSS v3.1
7.7
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 8.0.0.4
Description
OpenEMR is an electronic health records and medical practice management application. A Broken Access Control issue exists that allows users with limited privileges to view and download Ensora eRx error logs without authorization. This compromises the confidentiality of the system and could lead to unauthorized disclosure of sensitive information.
Recommendations
Update to a version later than 8.0.0.3.
Exploit
Correção
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openemr