CVE-2015-4453
Open-emr Openemr - Authentication Bypass
Title source: ruleDescription
interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive information via an ignoreAuth=1 value to certain scripts, as demonstrated by (1) interface/fax/fax_dispatch_newpid.php and (2) interface/billing/sl_eob_search.php.
References (6)
Scores
EPSS
0.4087
EPSS Percentile
97.3%
Classification
CWE
CWE-287
Status
draft
Affected Products (10)
open-emr/openemr
open-emr/openemr
open-emr/openemr
open-emr/openemr
open-emr/openemr
open-emr/openemr
open-emr/openemr
open-emr/openemr
open-emr/openemr
open-emr/openemr
Timeline
Published
Jul 05, 2015
Tracked Since
Feb 18, 2026