VYPR

Patient Portal

by Openemr

CVEs (2)

  • CVE-2020-36243HigFeb 7, 2021
    risk 0.62cvss 8.8epss 0.64

    The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.

  • CVE-2021-32101HigMay 7, 2021
    risk 0.53cvss 8.2epss 0.01

    The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the…