Medium severity6.5NVD Advisory· Published Sep 1, 2021· Updated Jun 17, 2026
CVE-2021-40352
CVE-2021-40352
Description
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- OpenEMR/OpenEMRdescription
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/164011/OpenEMR-6.0.0-Insecure-Direct-Object-Reference.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.open-emr.org/wiki/index.php/Securing_OpenEMRnvdProductVendor Advisory
News mentions
0No linked articles in our index yet.