packetstormsecurity.com
http://packetstormsecurity.com/files/164011/OpenEMR-6.0.0-Insecure-Direct-Object-Reference.html CVE-2021-40352
MEDIUM
OpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR)
Record summary
CVE-2021-40352 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Proofs of concept
2Catalogued exploits
ExploitDBOpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR)ExploitDB exploitby Allen Enosh UpputoriNot analyzed1 file
Repository PoCs
GitHuballenenosh/CVE-2021-40352Repository PoCby allenenoshStars: 3Not analyzed4 files
References
4github.com
https://github.com/allenenosh/CVE-2021-40352 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-40352 open-emr.org
https://www.open-emr.org/wiki/index.php/Securing_OpenEMR