CVE-2021-40352

Publication date

2021-09-01 12:20:41

Family

mitre

State

PUBLISHED

Description

OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.