CVE-2018-10572 - CERT CVE
ID CVE-2018-10572
Sažetak interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the newtemplatename and form_body parameters.
Reference
CVSS
Base: 5.5
Impact: 4.9
Exploitability:8.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL PARTIAL
CVSS vektor AV:N/AC:L/Au:S/C:N/I:P/A:P
Zadnje važnije ažuriranje 03-10-2019 - 00:03
Objavljeno 30-04-2018 - 17:29