Cross-Site Request Forgery Vulnerability in OpenEMR by OpenEMR Project
CVE-2020-13569
8.8HIGH
What is CVE-2020-13569?
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR, allowing attackers to execute arbitrary requests using a specially crafted HTTP request. This can have significant security implications as it operates within the context of the user's session, potentially compromising sensitive data or actions without the user's consent.
Affected Version(s)
OpenEMR OpenEMR 5.0.2 OpenEMR development version 6.0.0 (commitbabec93f600ff1394f91ccd512bcad85832eb6ce)
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
CVSS V3.0
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
