Improper access control in OpenMRS - #VU129552
Published: January 30, 2025 / Updated: May 4, 2026
OpenMRS
Detailed vulnerability description
The vulnerability allows a remote user to access restricted administrative functionality.
The vulnerability exists due to improper access control in administrative functions when handling authenticated requests. A remote user can access administrative endpoints or features to access restricted administrative functionality.