VYPR
Medium severity6.5NVD Advisory· Published Apr 11, 2022· Updated Jun 17, 2026

CVE-2022-1067

CVE-2022-1067

Description

Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting.

Affected products

2
  • cpe:2.3:a:lifepoint:patient_portal:*:*:*:*:*:*:*:*
    Range: <lpi_3.5.12.p30
  • LifePoint Informatics/Patient Portalv5
    Range: All

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.