CVE-2021-32101
Last modified
CVE-2021-32101 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. EPSS estimates a 1.18% chance of exploitation in the next 30 days.
Description
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Open-Emr | Openemr | 5.0.2.1 |
References
- https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerabilityThird Party Advisory
- https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerabilityThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32101?
How severe is CVE-2021-32101?
How do I fix CVE-2021-32101?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32095U.S. National Security Agency (NSA) Emissary 5.9.0 allows an…8.1
- CVE-2021-32096The ConsoleAction component of U.S. National Security Agency…8.8
- CVE-2021-32098Artica Pandora FMS 742 allows unauthenticated attackers to p…9.8
- CVE-2021-32099A SQL injection vulnerability in the pandora_console compone…9.8
- CVE-2021-3210components/Modals/HelpTexts/GenericAll/GenericAll.jsx in Blo…9.6
- CVE-2021-32100A remote file inclusion vulnerability exists in Artica Pando…6.5
- CVE-2021-32102A SQL injection vulnerability exists (with user privileges) …8.8
- CVE-2021-32103A Stored XSS vulnerability in interface/usergroup/usergroup_…4.8
- CVE-2021-32104A SQL injection vulnerability exists (with user privileges) …8.8
- CVE-2021-32106In ICEcoder 8.0 allows, a reflected XSS vulnerability was id…5.4
- CVE-2021-32122Certain NETGEAR devices are affected by CSRF. This affects E…8
- CVE-2021-32132The abst_box_size function in GPAC 1.0.1 allows attackers to…5.5
Are you affected by CVE-2021-32101?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
