Cross-Site Request Forgery Vulnerability in OpenEMR by OpenEMR Project
CVE-2020-13569

8.8HIGH

Key Information:

Vendor

Open-emr

Status
Vendor
CVE Published:
28 January 2021

What is CVE-2020-13569?

A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR, allowing attackers to execute arbitrary requests using a specially crafted HTTP request. This can have significant security implications as it operates within the context of the user's session, potentially compromising sensitive data or actions without the user's consent.

Affected Version(s)

OpenEMR OpenEMR 5.0.2 OpenEMR development version 6.0.0 (commitbabec93f600ff1394f91ccd512bcad85832eb6ce)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

CVSS V3.0

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.