Access Control Weakness in OpenEMR Patient Portal by OpenEMR
CVE-2021-32101
8.2HIGH
What is CVE-2021-32101?
The Patient Portal of OpenEMR version 5.0.2.1 is vulnerable due to an improper access control mechanism located in portal/patient/_machine_config.php. This allows unauthenticated attackers to register an account and bypass critical permission checks within the portal's API. Once registered, attackers can access and manipulate sensitive data belonging to all registered patients, posing significant risks to patient privacy and security.
