CyberRota Analysis
AI-GeneratedOpenEMR versions up to 8.2.0 are vulnerable to an authentication bypass that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting an unauthenticated client registration endpoint. This vulnerability enables attackers to register an OAuth2 client and obtain an API access token, undermining the security of the system. Organizations using OpenEMR should prioritize patching this vulnerability to protect against potential unauthorized access and data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.
Related CVEs
Other vulnerabilities affecting the same vendor(s)