Vulnerability Description
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
CVSS Score
8.3
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open-Emr | Openemr | < 6.1.0.1 |
Related Weaknesses (CWE)
References
- https://github.com/openemr/openemr/commit/8f8a97724c0e8fcc4096b4b30af9aaf064ada4PatchThird Party Advisory
- https://huntr.dev/bounties/9023ca9b-a601-4e5d-8952-640c60d029f1ExploitPatchThird Party Advisory
- https://github.com/openemr/openemr/commit/8f8a97724c0e8fcc4096b4b30af9aaf064ada4PatchThird Party Advisory
- https://huntr.dev/bounties/9023ca9b-a601-4e5d-8952-640c60d029f1ExploitPatchThird Party Advisory
FAQ
What is CVE-2022-1459?
CVE-2022-1459 is a vulnerability with a CVSS score of 8.3 (HIGH). Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
How severe is CVE-2022-1459?
CVE-2022-1459 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1459?
Check the references section above for vendor advisories and patch information. Affected products include: Open-Emr Openemr.