Record summary

CVE-2021-40352 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBOpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR)ExploitDB exploitby Allen Enosh UpputoriNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHuballenenosh/CVE-2021-40352Repository PoCby allenenoshStars: 3Not analyzed4 files

121.6 KiB

GitHub

PoC details

References

4